12.07.2015 Views

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Application Penetration Test for Super Veda- Sample Report -An attacker can directly call the updatebasket.asp page with differentquantities. The major danger of this is the ability of the attacker toinject negative quantities to the updatebasket.asp page, which willresult in a negative price for the products! Since the total amount ofproducts is summed later on, the attacker can manipulate the total ofall his purchase to be very low or zero, instead of negative, and thusavoid being noticed by any later inspection of the price order.ImpervaPage26 of73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!