Which tool can be useful when testing parameter manipulation?
Proxy
Which of the following is not a common CMS (Content Management System)?
PressWord
Which of the following is a common vulnerability for Drupal?
Druppalgeddon
What is the difference between WWW and the internet?
WWW is indexed pages
What is one of the reasons that command injection may exist?
lack of input validation
Is it possible to manipulate hidden parameters in a proxy?
Yes
What is needed for CSRF to be successful?
Cookie based session handling
www.northgreen-insecure.com/server.php?cmd=pwd may be vulnerable to what kind of attack?
Command Injection
Which vulnerability is most likely to lead to an attacker attempting privilege escalation on the underlying web server?
Command Injection
What is a key risk of CMS platforms?
One vulnerability could impact multiple sites