Skip to content
PT0-003
Attacks and Exploits
medium
Question 16 of 34

A penetration tester is conducting a web application test and identifies that the application reflects user input in the page response without encoding. Which attack is this application MOST vulnerable to?

ASQL injection
BCross-site scripting (XSS)
CDirectory traversal
DXML external entity (XXE) injection

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion