kirancodes.me
To Proof Maintenance & Beyond!

Automatic creation of SQL Injection and cross-site scripting attacks

Adam Kiezun, Philip J. Guo, Karthick Jayaraman, Michael D. Ernst

Abstract

We present a technique for finding security vulnerabilities in Web applications. SQL Injection (SQLI) and cross-site scripting (XSS) attacks are widespread forms of attack in which the attacker crafts the input to the application to access or modify user data and execute malicious code. In the most serious attacks (called second-order, or persistent, XSS), an attacker can corrupt a database so as to cause subsequent users to execute malicious code.

BibTeX
@inproceedings{Kiezun-al:ICSE09,
  author    = {Adam Kiezun and
               Philip J. Guo and
               Karthick Jayaraman and
               Michael D. Ernst},
  title     = {Automatic creation of {SQL} Injection and cross-site scripting attacks},
  booktitle = {ICSE},
  pages     = {199--209},
  publisher = {{IEEE}},
  year      = {2009},
}

Related papers