CompTIA PenTest+ (PT0-003) PT0-003 — Question 257
Topic 1 · Question 257 of 334
Topic 1 · Question 257
During a web application assessment, a penetration tester accesses the site unauthenticated and receives the following Set-Cookie on the first response: auth=yYKGORbrpabgr842ajbvrpbptaui42342 When the tester logs in, the server sends only one Set-Cookie header, and the value is exactly the same as shown above. Which of the following vulnerabilities has the tester discovered?