A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2010; you can also visit the original URL.
The file type is application/pdf
.
Automatic creation of SQL Injection and cross-site scripting attacks
2009
2009 IEEE 31st International Conference on Software Engineering
We present a technique for finding security vulnerabilities in Web applications. SQL Injection (SQLI) and crosssite scripting (XSS) attacks are widespread forms of attack in which the attacker crafts the input to the application to access or modify user data and execute malicious code. In the most serious attacks (called second-order, or persistent, XSS), an attacker can corrupt a database so as to cause subsequent users to execute malicious code. This paper presents an automatic technique for
doi:10.1109/icse.2009.5070521
dblp:conf/icse/KiezunGJE09
fatcat:h57s2cimizbnnkeuqpnjtjky4q