GCIH Exploiting Insecure Web App References Practice Question
A penetration tester is reviewing a Java-based e-commerce application. The product page URL is `https://shop.example.com/product?pid=1042`. When the tester changes `pid` to `1043`, the application returns the details of a different product. The tester then changes `pid` to `1043'` and receives a detailed Java stack trace in the HTTP response. Which type of vulnerability is most directly indicated by the stack trace, and what should the tester do next to confirm the impact?
⚠ Common exam trap
The trap here is assuming that any parameter manipulation that returns different data is IDOR, when a database error from a quote character clearly points to SQL injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection; the tester should attempt to extract the database schema using UNION-based queries.
The application returns a detailed Java stack trace when a single quote is appended to a numeric parameter, which is a hallmark of SQL injection. The tester should leverage this error to extract database information, confirming the vulnerability's severity. The other options describe different attack classes that do not match the observed server-side database error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Path traversal; the tester should replace `pid` with `../../../../etc/passwd` to read system files.
Why it's wrong here
Path traversal targets file system operations, not database queries. The stack trace from a quote character strongly suggests SQL injection because the quote breaks the SQL syntax. Attempting path traversal would not produce a Java stack trace in this context and is unlikely to succeed if the parameter is used in a database query.
- ✓
SQL injection; the tester should attempt to extract the database schema using UNION-based queries.
Why this is correct
The stack trace from a single quote in a numeric parameter is a classic indicator of SQL injection. The application likely concatenates the `pid` value directly into a SQL query. To confirm impact, the tester should craft payloads to retrieve database metadata, such as table names and user credentials, using UNION SELECT or error-based techniques.
- ✗
Insecure Direct Object Reference (IDOR); the tester should create a second user account and attempt to access the first user's orders.
Why it's wrong here
IDOR involves accessing objects by manipulating identifiers without authorization, but the presence of a database error from a quote character points to improper input handling, not merely an access control flaw. The stack trace indicates the parameter is used in a SQL query, so SQL injection is the more direct vulnerability.
- ✗
Cross-site scripting (XSS); the tester should inject a script tag into the `pid` parameter and check if it executes in the browser.
Why it's wrong here
XSS would not typically cause a Java stack trace on the server side. The error is generated during server-side processing of the SQL query, not during client-side rendering. Injecting a script tag would test for reflected XSS, but it does not align with the observed database error.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.