nerdexam
Huawei

H13-831_V2.0 · Question #2492

A user uses dvwa software to perform vulnerability exploitation testing. On the software page, the user enters the following content in the input field: "></input><script>alret…

The correct answer is A. This page explains that attackers can steal users' accounts and perform operations by inducing B. This page indicates that the website has a cross-site scripting attack. See the full explanation below for the reasoning.

Advanced Network and Security Architecture Design

Question

A user uses dvwa software to perform vulnerability exploitation testing. On the software page, the user enters the following content in the input field: "></input><script>alret (1803)</script><input>, and submits it, and the following message appears. Which of the following descriptions of the output are correct? (Multiple choice)

Options

  • AThis page explains that attackers can steal users' accounts and perform operations by inducing
  • BThis page indicates that the website has a cross-site scripting attack
  • CThis page indicates that the website does not have cross-site scripting attacks
  • DThe page displays the "Hello" message normally, without any code injection risk.

How the community answered

(68 responses)
  • A
    81% (55)
  • C
    12% (8)
  • D
    7% (5)

Topics

#XSS#cross-site scripting#vulnerability testing#web security

Community Discussion

No community discussion yet for this question.

Full H13-831_V2.0 Practice