An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to:
URL: http://192.168.0.100/ERP/accountId=5&action=SELECT
Which of the following is the MOST likely vulnerability in this ERP platform?
A. Brute forcing of account credentials
B. Plan-text credentials transmitted over the Internet
C. Insecure direct object reference
D. SQL injection of ERP back end
How to PASS CAS-004 in First Attempt?FULL Printable PDF and Software. VALID exam to help you PASS. |
accountId=5&action=SELECT
D. SQL injection of ERP back end
Sorry
Correct answer is C. Insecure direct object reference
cuz SELECT command is “tricky” and not related to attack
ref:
Insecure Direct Object Reference (IDOR) — Web-based Application Security, Part 6
C