What Vulnerability Does a Script Tag in Web Logs Indicate?

While reviewing logs, a security administrator identifies the following code: Which of the following best describes the vulnerability being exploited? - image

  1. XSS Source Reference Answer
  2. SQLi
  3. DDoS
  4. CSRF

Community Votes

A
82%
B
18%

82% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Candidates must recognize that injected browser-executable code points to client-side vulnerabilities, avoiding the common trap of misidentifying it as a backend database attack.

This question tests the ability to identify Cross-Site Scripting (XSS) from malicious script tags found in web server logs. The community consensus strongly confirms that client-side code injection in logs is the hallmark of an XSS attack.

SQL Injection is frequently chosen due to the shared 'injection' terminology, but SQLi payloads contain database commands (like SELECT or UNION statements), whereas the log snippet explicitly contains JavaScript execution tags meant for browsers.

Community Discussion (6 comments)

chasingsummer 👍 5 Selected: A
The code snippet provided (<script>function (send_info)</script>) indicates the presence of a JavaScript function embedded within a webpage, which is typical of a cross-site scripting (XSS) attack.
45043df 👍 1 Selected: A
ChatGPT as of 01/01/2025: indicates the potential for Cross-Site Scripting (XSS). Reasoning: XSS (Cross-Site Scripting): This vulnerability occurs when attackers inject malicious scripts into webpages viewed by others. The presence of a <script> tag in the logs strongly suggests the possibility of XSS. If the script content includes malicious code, it could be executed in the context of the victim's browser. SQLi (SQL Injection): This pertains to injecting malicious SQL queries into database queries, which does not involve <script> tags or JavaScript. DDoS (Distributed Denial of Service): This involves overwhelming a service with traffic, which does not directly involve JavaScript or <script> tags in logs. CSRF (Cross-Site Request Forgery): This exploits trust in authenticated users to perform unwanted actions on their behalf, but it does not involve <script> tags or JavaScript injection. Correct Answer: a) XSS
jbmac 👍 1 Selected: A
The correct answer is: A. XSS (Cross-Site Scripting) Explanation: The code <script>function (send_info)</script> is a basic example of Cross-Site Scripting (XSS). In an XSS attack, an attacker injects malicious JavaScript code into web pages that can be executed in the context of another user's browser. This allows the attacker to steal sensitive information, such as session cookies, or perform other malicious actions, such as redirecting users or altering the content of the page.
ProudFather 👍 1 Selected: B
The code snippet demonstrates a classic example of SQL injection (SQLi). The attacker has injected malicious SQL code into the input field, bypassing the intended query and potentially gaining unauthorized access to the database.
0ca8ee9 👍 2 Selected: A
The code snippet <script>function (send_info)</script> by itself does not exploit a vulnerability. It's an incomplete piece of JavaScript code. However, its presence in logs, especially in contexts like URLs or web server logs, strongly suggests an attempted Cross-Site Scripting (XSS) attack.
4617f0b 👍 1 Selected: B
Explanation according to ChatGPT: The code in the log likely contains evidence of an SQL Injection (SQLi) attack. Here’s why: SQL Injection (SQLi) is an attack technique where an attacker exploits a vulnerability in an application's software by injecting malicious SQL code into an input field (such as a form field, URL parameter, or API input). This can lead to unauthorized access to the database, data leakage, or even data modification. In the logs, if the attacker is attempting to inject SQL keywords such as UNION, SELECT, OR, AND, or similar, it is a strong indicator of an SQLi attack. These are typical components of SQL injection queries used to manipulate the database query.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Identifying the Attack Vector

The log snippet displays a <script> tag containing a JavaScript function. This is a definitive signature of Cross-Site Scripting (XSS). In an XSS attack, an attacker injects malicious client-side scripts into webpages viewed by other users. When the victim's browser renders this code, it executes within the trusted context of the target website.

Why XSS is the Correct Answer

Option A is correct because web server logs often capture raw HTTP request bodies or URL parameters. The presence of <script> tags indicates that user input was reflected or stored without proper sanitization, allowing arbitrary JavaScript to run. As highlighted by multiple candidates in the community discussions, seeing JS functions or DOM manipulation code in logs directly correlates to XSS exploitation attempts.

Eliminating Incorrect Options

  • SQL Injection (B) targets relational databases using SQL syntax. Payloads typically include quotes, comments (--, / /), or logical operators (OR 1=1). The provided code lacks any database-specific commands, making this a distractor for those relying on keyword association rather than payload analysis.
  • DDoS (C) involves overwhelming a system with traffic volume, not injecting executable code snippets into application logs.
  • CSRF (D) exploits authenticated sessions by tricking users into submitting unintended requests. It does not require injecting <script> tags into the application itself; instead, it relies on social engineering and token validation flaws.

Exam Context

Security+ frequently tests payload recognition. Always analyze the syntax of the log entry: HTML/JS tags = XSS, SQL keywords = SQLi, massive concurrent connections = DDoS, and forged state-changing requests = CSRF.

Official Reference

Exam Strategy

When presented with log excerpts or code snippets, immediately categorize the syntax by its intended execution environment: browser tags indicate client-side issues, while query strings or database operators point to backend vulnerabilities. Practicing payload pattern recognition will allow you to eliminate distractors rapidly and avoid overthinking purely semantic similarities.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide