Courseiva

CEH

Study mode — explanations shown

1

Web Application and Injection Attacks

medium

A penetration tester discovers that a web application's search functionality reflects user input directly in the page source without sanitization. The tester crafts a URL like http://example.com/search?q=<script>alert('XSS')</script> and the script executes. This is an example of which type of XSS?

0 of 125 answered