November 2017
Intermediate to advanced
452 pages
11h 46m
English
Using the following table, we will choose one threat and find out its risk rating:
|
Threat risk rating: Attacker could dump database contents via SQL injection |
|
|
Item |
Score |
|
Damage potential |
3 |
|
Reproducibility |
3 |
|
Exploitability |
2 |
|
Affected users |
3 |
|
Discoverability |
2 |
|
Risk Rating Score: High |
13 |
Clearly, there is more of a payoff to exploit vulnerabilities in the vendor's SaaS application given that there are loads of users' details with additional features available. However, it is important to stay within legal bounds and gain authorization prior to testing. Targeting the embedded web applications may not give as big of a reward up front but it is definitely possible ...
Read now
Unlock full access