The finance department for an online shopping website has discovered that a number of customers were able
to purchase goods and services without any payments. Further analysis conducted by the security
investigations team indicated that the website allowed customers to update a payment amount for shipping. A
specially crafted value could be entered and cause a roll over, resulting in the shipping cost being subtracted
from the balance and in some instances resulted in a negative balance. As a result, the system processed the
negative balance as zero dollars. Which of the following BEST describes the application issue?
A.
Race condition
B.
Click-jacking
C.
Integer overflow
D.
Use after free
E.
SQL injection