Collected research
Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications
PAPAS, a Firefox-driven black-box scanner, injects an encoded query delimiter into each existing parameter and checks whether it reappears inside the page's links and form actions. A 13-day crawl of 5,016 popular sites found about 30% with injectable parameters and confirmed 46.8% of those exploitable, including Google, PayPal, Symantec and Microsoft.
Record
- Researcher
- Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti and Engin Kirda
- Published by
- NDSS Symposium
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .