CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A penetration tester submits the string ' OR '1'='1 into a website's login username field and successfully bypasses authentication. Which vulnerability was exploited?
- ADirectory traversal
- BSQL injection
- CBuffer overflow
- DCross-site request forgery
Show answer & explanationAnswer & explanation
Correct answer: B. SQL injection
The payload ' OR '1'='1 manipulates a SQL WHERE clause so it always evaluates to true, bypassing authentication logic—this is a classic SQL injection attack against unsanitized input in a database query.
Why the other options are wrong
- A. Directory traversal manipulates file paths, not database queries.
- C. Buffer overflow involves memory corruption from oversized input, not query logic manipulation.
- D. CSRF forces a user's browser to submit unwanted requests using their existing session, unrelated to this payload.
SQL Injection
An attack that inserts malicious SQL code into input fields to manipulate or bypass database queries.
- Common payload: ' OR '1'='1
- Mitigated with parameterized queries/prepared statements
- Can lead to data theft, authentication bypass, or database modification
Memory trick: Inject truth into the query and the door swings open.