Q: 7
[Handling and Responding to Web Application Attacks]
Oscar receives an email from an unknown source containing his domain name oscar.com. Upon
checking the link, he found that it contains a malicious URL that redirects to the website evilsite.org.
What type of vulnerability is this?
Options
Discussion
Option C makes more sense here. The key part is the malicious URL redirecting to evilsite.org, which fits unvalidated redirects and forwards from OWASP. D (SQL injection) would need details about database queries, but nothing in the scenario suggests that. Easy to mix up if you just see "malicious URL" though! Pretty sure it's C, open to discussion if I'm missing something.
C or D? Saw a question like this in a practice set and thought D at first because links can sometimes trigger SQL injection, but the redirect part throws me off. Anyone else remember this from ECIH materials?
Be respectful. No spam.