Detection and Removing Cross Site Scripting Vulnerability in PHP Web Application

Abdalla Wasef Marashdih, Zarul Fitri Zaaba · 2017

Cross Site Scripting (XSS) vulnerability acts as one of the chief widespread security issues in web applications. By reviewing the literature pertaining to XSS vulnerability, it has been found that many investigations have directed their energy only on XSS vulnerability detection, but not many studies have concentrated on removing XSS vulnerability. This paper embed the removal stage of XSS vulnerability to our previous approach of detection XSS vulnerability, in a way to make the approach fully to detect and remove XSS vulnerability from PHP source code. We conducted two experiments to detect and remove Reflected and Stored XSS vulnerability. The results show that our approach is able to detect and remove XSS vulnerability in PHP source code. More research is required in the field of removing XSS vulnerability from the application source code before deployment.

Read the paper · More papers on PaperTik