Automatic creation of SQL Injection and cross-site scripting attacks

Adam Kieyzun, Philip J. Guo, Karthick Jayaraman, Michael D. Ernst · 2009

We present a technique for finding security vulnerabilities in Web applications. SQL Injection (SQLI) and cross-site scripting (XSS) attacks are widespread forms of attack in which the attacker crafts the input to the application to access or modify user data and execute malicious code. In the most serious attacks (called second-order, or persistent, XSS), an attacker can corrupt a database so as to cause subsequent users to execute malicious code.

Read the paper · More papers on PaperTik