CompTIA CySA+ (CS0-003)Security OperationsMedium

A web application firewall log shows the following request against a public e-commerce site: `192.168.1.15 - - [10/Mar/2024:14:22:07 +0000] "GET /products.php?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 1523` Which type of attack does this log entry MOST likely indicate?

  1. ACommand injection
  2. BDirectory traversal
  3. CSQL injection
  4. DCross-site scripting (XSS)
Show answer & explanation

Correct answer: C. SQL injection

The request injects a `UNION SELECT` statement into the `id` parameter, attempting to append a second query that pulls usernames and passwords from the `users` table — a textbook SQL injection technique. The trailing `--` comments out the rest of the original query to keep the syntax valid.

Why the other options are wrong

  • A. Command injection targets OS shell commands (e.g., ; whoami), not SQL syntax.
  • B. Directory traversal uses sequences like ../../ to access files outside the web root.
  • D. XSS would involve injected `<script>` tags, not SQL syntax.

SQL Injection Indicator

An attack technique where malicious SQL syntax is inserted into an input field to manipulate backend database queries.

  • UNION SELECT combines results from an injected query
  • Trailing -- or # comments out remaining original SQL
  • Often targets parameters like id, search, or login fields

Memory trick: UNION SELECT unions the attacker with your data.

More Security Operations questions