Collected research
Static Detection of Second-Order Vulnerabilities in Web Applications
Web applications often store attacker input in a database, session key or file name and use it in a sensitive sink much later, so taint analysis that stops at one request misses it. This work models those persistent stores statically and found 159 second-order flaws, including stored XSS, SQL injection and remote command execution in osCommerce, OpenConf and NewsPro.
Record
- Researcher
- Johannes Dahse and Thorsten Holz
- Published by
- usenix.org
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Johannes Dahse and Thorsten Holz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .