Highlights
Task:
1 Overview
The learning objective of this assignment is for you to gain a first-hand experience on SQL injection attacks and cross-site scripting attacks and get a deeper understanding on how to exploit the vulnerability in real- world web applications. All tasks in this assignment can be done on “SeedVM” as used in labs.
SQL Injection Attack – Using SQLi Lab [50 Marks]
SQL injection is a code injection technique that exploits the vulnerabilities in the interface between web ap- plications and database servers. The vulnerability is presented when user’s inputs are not correctly checked within the web applications before sending to the back-end database servers. Many web applications take inputs from users, and then use these inputs to construct SQL queries, so the web applications can pull the information out of the database. Web applications also use SQL queries to store information in the database. These are common practices in the development of web applications. When the SQL queries are not carefully constructed, SQL-injection vulnerabilities can occur. SQL-injection attacks is one of the most frequent attacks on web applications.
Task 1: SQL Injection Attack on SELECT Statements [5 Marks]
In this task, you need to manage to log into SQLi Lab at www.seedlabsqlinjection.com, without providing a password. You can achieve this by using SQL injection. Normally, before users start using SQLi Lab, they need to login using their user names and passwords. SQLi Lab displays a login window to users and ask them to input username and password.
Task 2: SQL Injection on UPDATE Statements [10 Marks]
In this task, you need to make an unauthorised modification to the database. Your goal is to modify another user’s profile using SQL injections. In SQLi Lab, if users want to update their profiles, they can click the Edit Profile link on the navigation bar, and then fill out a form to update the profile information. After the user sends the update request to the server, an UPDATE SQL statement will be constructed in unsafe edit backend.php. The objective of this statement is to modify the current user’s profile information in the credential table.
This Computer Science Assignment has been solved by our Computer Science Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.