Web Hack List

Collected research

Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web Applications

Studies authentication bypasses caused by disagreement between Java URL routing and access checks. UABScan extracts framework routing features, slices URL-dependent code, and matches risky checks against sanitization patterns. Across 529 applications it reports 94 candidates; verification confirms 56 vulnerabilities, including 35 new ones, with 80% precision among checked findings.

Record

Researcher
Qiyi Zhang, Fengyu Liu, Zihan Lin and Yuan Zhang
Published by
ACM CCS
Format
Whitepaper
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Qiyi Zhang, Fengyu Liu, Zihan Lin and Yuan Zhang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .