EARs in the wild

Pierre Payet, Adam Doupé, Christopher Kruegel, Giovanni Vigna · 2013

Execution After Redirect vulnerabilities---logic flaws in web applications where unintended code is executed after a redirect---have received little attention from the research community. In fact, we found a research paper that incorrectly modeled the redirect semantics, causing their static analysis to miss EAR vulnerabilities.

Read the paper · More papers on PaperTik