Courseiva

GCIH Web App Injection Attacks Practice Question

An incident handler is investigating a web application that uses a templating engine. The application allows users to submit their name, which is later rendered in a greeting page. An attacker submits the payload `{{7*7}}` and the page displays `49`. The application also exposes an endpoint that accepts a template name as a parameter. Which vulnerability is most likely present?

⚠ Common exam trap

The trap here is mistaking template expression evaluation for harmless arithmetic or for client-side XSS, when the server-side evaluation itself is the vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-Side Template Injection (SSTI)

The evaluation of `{{7*7}}` to `49` demonstrates that the application processes user input as a template expression. This is Server-Side Template Injection, which can lead to remote code execution depending on the engine. The secondary endpoint that accepts a template name further increases risk. Incident responders should isolate the application, review template engine logs, and check for any uploaded or modified templates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Server-Side Template Injection (SSTI)

    Why this is correct

    The payload `{{7*7}}` being evaluated to `49` indicates that user input is being processed as a template expression rather than plain text. This is the hallmark of Server-Side Template Injection. The additional endpoint accepting a template name increases the attack surface, potentially allowing template path traversal or remote code execution depending on the engine. Incident handlers should treat this as a high-severity finding.

  • ✗

    Insecure deserialization

    Why it's wrong here

    Insecure deserialization involves manipulating serialized objects to achieve code execution or other impacts. The scenario does not mention serialized data; it describes user input being rendered as a template. The evaluation of `{{7*7}}` to `49` is a classic template injection test, not a deserialization gadget. Therefore, this option does not match the observed behavior.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection manipulates database queries, typically using SQL syntax like quotes, UNION, or boolean conditions. The payload `{{7*7}}` is not SQL and would not be evaluated by a database as arithmetic in a query context. The result `49` appearing in the rendered page suggests the templating engine, not the database, processed the expression. Thus SQL injection is not the primary vulnerability here.

  • ✗

    Reflected Cross-Site Scripting (XSS)

    Why it's wrong here

    Reflected XSS would execute JavaScript in the victim's browser, but the payload `{{7*7}}` is not JavaScript; it is template syntax. The fact that the server evaluated it to `49` before sending the response proves server-side processing. XSS does not cause arithmetic evaluation on the server. Therefore, while the application may also have XSS, the observed behavior is specific to template injection.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.