Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A web application allows users to upload profile pictures. The upload functionality is handled by `upload.php`, which saves files to `/var/www/uploads/` and returns a URL like `https://example.com/uploads/username.jpg`. A security tester notices that the application does not validate the file type and that the upload directory is web-accessible. The tester uploads a file named `shell.php` containing PHP code and then navigates to `https://example.com/uploads/shell.php`. The server executes the PHP code. Which vulnerability has the tester exploited?

⚠ Common exam trap

Watch out — candidates often confuse file upload vulnerabilities with path traversal, when the key issue is the server executing an uploaded script.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unrestricted file upload leading to remote code execution.

The tester uploaded a PHP file that the server executed, demonstrating remote code execution due to lack of file type validation. The other options describe different vulnerabilities: path traversal involves directory manipulation, IDOR involves unauthorized access to objects, and XSS involves client-side script injection. None of these match the server-side execution of an uploaded file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Insecure Direct Object Reference (IDOR) allowing access to other users' files.

    Why it's wrong here

    IDOR occurs when an application exposes a reference to an internal object without access control, allowing users to access others' data. In this scenario, the tester uploaded a malicious file and executed it; the issue is not about accessing another user's object but about the server executing arbitrary code.

  • ✗

    Cross-site scripting (XSS) via uploaded image files.

    Why it's wrong here

    XSS involves injecting client-side scripts into web pages viewed by other users. While uploaded files can sometimes lead to XSS if they contain scripts and are served with the wrong content type, here the tester uploaded a PHP file that executed on the server, not in a victim's browser. This is a server-side code execution issue.

  • ✗

    Path traversal allowing access to files outside the web root.

    Why it's wrong here

    Path traversal involves manipulating file paths to access directories outside the intended scope. Here, the tester uploaded a file to a web-accessible directory and executed it directly; no path manipulation was used to traverse directories. The vulnerability is the lack of file type validation, not path traversal.

  • ✓

    Unrestricted file upload leading to remote code execution.

    Why this is correct

    The application fails to validate the file type, allowing the tester to upload a PHP file that is then executed by the web server. This is a classic unrestricted file upload vulnerability that leads to remote code execution, as the attacker can run arbitrary commands on the server.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.