Certified Ethical Hacker (CEH) Practice Question

During a web application test you log in as a standard user and notice the profile page URL ends with id=1042. Manually changing the id parameter to 1041 returns another customer's profile without triggering any authorization error. Which access-control weakness is being exploited in this situation?

  • SQL injection caused by unsanitized numeric parameters

  • Session fixation through predictable session identifiers

  • Insecure Direct Object Reference that allows horizontal privilege escalation

  • Cross-Site Request Forgery that forces unauthorized requests

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot