Fortifying Applications Against XPath Injection Attacks

Dimitrios Mitropoulos, Vassilios Karakoidas, Diomidis D. Spinellis · Journal of the Association for Information Systems · 2009

Code injection derives from a software vulnerability that allows a malicious user to inject custom code into the server engine. In recent years, there have been a great number of such exploits targeting web applications. In this paper we propose an approach that prevents a specific kind of code injection attacks known as xpath injection in a novel way. To detect an attack, our scheme uses location-specific identifiers to validate the executable xpath code. These identifiers represent all the unique fragments of this code along with their call sites within the application.

Read the paper · More papers on PaperTik