CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A tester crafts a URL such as http://shop.example.com/search?q=<script>alert(1)</script> and sends it to a victim. When the victim clicks the link, the search results page reflects the query string back into the HTML without encoding, and the script executes in the victim's browser. Which type of vulnerability is this?

  1. ADOM-based cross-site scripting
  2. BCross-site request forgery
  3. CReflected cross-site scripting
  4. DStored cross-site scripting
Show answer & explanation

Correct answer: C. Reflected cross-site scripting

The payload comes from the URL/query string and is immediately reflected in the server's response without being stored, requiring the victim to click a crafted link — the hallmark of reflected XSS.

Why the other options are wrong

  • A. DOM-based XSS executes purely via client-side JavaScript manipulation, not server reflection.
  • B. CSRF forces a victim to perform an unwanted action, not inject script into a page.
  • D. Stored XSS would persist the payload in a database and affect all future viewers, not just link clickers.

Reflected XSS

A cross-site scripting attack where malicious input is immediately echoed back by the server in the HTTP response, typically requiring a victim to click a crafted link.

  • Payload travels in the request (URL/query/form) and is reflected in the response
  • Not stored on the server; requires social engineering to deliver the link
  • Mitigated by output encoding and Content Security Policy

Memory trick: Reflected = mirror bounces script back instantly

More Attacks and Exploits questions