nerdexam
EC-Council

EC0-350 · Question #425

During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to exploit this…

The correct answer is B. The session cookies do not have the HttpOnly flag set. See the full explanation below for the reasoning.

Question

During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to exploit this vulnerability?

Options

  • AThe web application does not have the secure flag set.
  • BThe session cookies do not have the HttpOnly flag set.
  • CThe victim user should not have an endpoint security solution.
  • DThe victim's browser must have ActiveX technology enabled.

How the community answered

(47 responses)
  • A
    13% (6)
  • B
    77% (36)
  • C
    4% (2)
  • D
    6% (3)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice