Question: An attacker inserts SQL database commands into a data input field of an order form used by a web - based application. When submitted, these
An attacker inserts SQL database commands into a data input field of an order form used by a webbased application. When submitted, these commands are executed on the remote database server, causing customer contact information from the database to be sent to the malicious user's web browser.
Which practice would have prevented this exploit?
answer
Implementing clientside validation
Installing antivirus, antispyware, popup blockers, and firewall software
Using the latest browser version and patch level
Implementing a script blocker
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
