Huawei
H13-831_V2.0 · Question #2492
A user uses dvwa software to perform vulnerability exploitation testing. On the software page, the user enters the following content in the input field: "></input><script>alret…
The correct answer is A. This page explains that attackers can steal users' accounts and perform operations by inducing B. This page indicates that the website has a cross-site scripting attack. See the full explanation below for the reasoning.
Advanced Network and Security Architecture Design
Question
A user uses dvwa software to perform vulnerability exploitation testing. On the software page, the user enters the following content in the input field: "></input><script>alret (1803)</script><input>, and submits it, and the following message appears. Which of the following descriptions of the output are correct? (Multiple choice)
Options
- AThis page explains that attackers can steal users' accounts and perform operations by inducing
- BThis page indicates that the website has a cross-site scripting attack
- CThis page indicates that the website does not have cross-site scripting attacks
- DThe page displays the "Hello" message normally, without any code injection risk.
How the community answered
(68 responses)- A81% (55)
- C12% (8)
- D7% (5)
Topics
#XSS#cross-site scripting#vulnerability testing#web security
Community Discussion
No community discussion yet for this question.