EC-Council
EC0-350 · Question #309
An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been…
The correct answer is B. By changing hidden form values. See the full explanation below for the reasoning.
Question
An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the Intrusion Detection System (IDS) logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the purchase price?
Options
- ABy using SQL injection
- BBy changing hidden form values
- CBy using cross site scripting
- DBy utilizing a buffer overflow attack
How the community answered
(44 responses)- A7% (3)
- B77% (34)
- C5% (2)
- D11% (5)
Community Discussion
No community discussion yet for this question.