{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T22:31:09Z","timestamp":1766269869699},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540705413"},{"type":"electronic","value":"9783540705420"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-70542-0_7","type":"book-chapter","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T16:07:43Z","timestamp":1218557263000},"page":"126-142","source":"Crossref","is-referenced-by-count":19,"title":["On Race Vulnerabilities in Web Applications"],"prefix":"10.1007","author":[{"given":"Roberto","family":"Paleari","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Davide","family":"Marrone","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Danilo","family":"Bruschi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mattia","family":"Monga","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"NCSA Software Development Group: The Common Gateway Interface (1995)","key":"7_CR1"},{"unstructured":"Kunze, M.: Let there be light. LAMP: Freeware web publishing system with database support. c\u2019t 12, 230 (1998)","key":"7_CR2"},{"key":"7_CR3","volume-title":"Testing and Analysis of Web Services","author":"M. Cova","year":"2007","unstructured":"Cova, M., Felmetsger, V., Vigna, G.: Vulnerability Analysis of Web Applications. In: Baresi, L., Dinitto, E. (eds.) Testing and Analysis of Web Services. Springer, Heidelberg (2007)"},{"unstructured":"Symantec Inc.: Symantec internet security threat report: Volume XII. Technical report, Symantec Inc. (September 2007)","key":"7_CR4"},{"unstructured":"Halfond, W.G., Viegas, J., Orso, A.: A Classification of SQL-Injection Attacks and Countermeasures. In: Proceedings of the IEEE International Symposium on Secure Software Engineering, Arlington, VA, USA (2006)","key":"7_CR5"},{"unstructured":"CERT: Advisory CA-2000-02: Malicious HTML Tags Embedded in Client Web Requests (2002)","key":"7_CR6"},{"issue":"1","key":"7_CR7","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/130616.130623","volume":"1","author":"R.H.B. Netzer","year":"1992","unstructured":"Netzer, R.H.B., Miller, B.P.: What are Race Conditions?: Some Issues and Formalizations. ACM Letters on Programming Languages and Systems\u00a01(1), 74\u201388 (1992)","journal-title":"ACM Letters on Programming Languages and Systems"},{"unstructured":"Dean, D., Hu, A.J.: Fixing races for fun and profit: How to use access(2). In: Proceedings of the 13th conference on USENIX Security Symposium (2004)","key":"7_CR8"},{"unstructured":"Borisov, N., Johnson, R., Sastry, N., Wagner, D.: Fixing races for fun and profit: How to abuse atime. In: Proceedings of the 14th conference on USENIX Security Syposium (2005)","key":"7_CR9"},{"issue":"2","key":"7_CR10","first-page":"131","volume":"2","author":"M. Bishop","year":"1996","unstructured":"Bishop, M., Dilger, M.: Checking for race conditions in file accesses. Computing Systems\u00a02(2), 131\u2013152 (1996)","journal-title":"Computing Systems"},{"unstructured":"Abbott, R.P., Chin, J.S., Donnelley, J.E., Konigsford, W.L., Tokubo, S., Webb, D.A.: Security analysis and enhancements of computer operating systems.","key":"7_CR11"},{"unstructured":"phpBB Group: phpBB","key":"7_CR12"},{"unstructured":"Joomla! Core Team: Joomla!","key":"7_CR13"},{"unstructured":"Jovanovic, N.: Web Application Security. PhD thesis, Technical University of Vienna (July 2007)","key":"7_CR14"},{"doi-asserted-by":"crossref","unstructured":"Hind, M.: Pointer analysis: Haven\u2019t we solved this problem yet? In: 2001 ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools and Engineering (PASTE 2001) (2001)","key":"7_CR15","DOI":"10.1145\/379605.379665"},{"unstructured":"PHP Documentation Group: PHP Manual. [Online; accessed 23-November-2007].","key":"7_CR16"},{"unstructured":"MySQL AB: MySQL Reference Manual, http:\/\/dev.mysql.com\/doc\/refman\/5.0 .","key":"7_CR17"},{"unstructured":"Sterling, N.: WARLOCK - A static data race analysis tool. In: Proceedings of the Usenix Winter 1993 Technical Conference, pp. 97\u2013106 (1993)","key":"7_CR18"},{"doi-asserted-by":"crossref","unstructured":"Engler, D., Ashcraft, K.: RacerX: Effective, Static Detection of Race Conditions and Deadlocks. In: Proceedings of the Nineteenth ACM Symposium on Operating Systems Principles, pp. 237\u2013252 (2003)","key":"7_CR19","DOI":"10.1145\/945445.945468"},{"issue":"5","key":"7_CR20","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1145\/358438.349328","volume":"35","author":"C. Flanagan","year":"2000","unstructured":"Flanagan, C., Freund, S.N.: Type-based race detection for Java. ACM SIGPLAN Notices\u00a035(5), 219\u2013232 (2000)","journal-title":"ACM SIGPLAN Notices"},{"doi-asserted-by":"crossref","unstructured":"Boyapati, C., Rinard, M.: A parameterized type system for race-free java programs. In: Proceedings of the 16th ACM SIGPLAN conference on Object oriented programming, systems, languages, and applications, pp. 56\u201369 (2001)","key":"7_CR21","DOI":"10.1145\/504282.504287"},{"doi-asserted-by":"crossref","unstructured":"Dinning, A., Schonberg, E.: An empirical comparison of monitoring algorithms for access anomaly detection. In: Proceedings of the Second ACM SIGPLAN Symposium on Principles & Practice of Parallel Programming, pp. 1\u201310 (1990)","key":"7_CR22","DOI":"10.1145\/99163.99165"},{"issue":"2","key":"7_CR23","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1145\/312203.312214","volume":"17","author":"M. Ronsse","year":"1999","unstructured":"Ronsse, M., Bosschere, K.D.: RecPlay: A fully integrated practical record\/replay system. ACM Transactions Computer Systems\u00a017(2), 133\u2013152 (1999)","journal-title":"ACM Transactions Computer Systems"},{"issue":"7","key":"7_CR24","doi-asserted-by":"publisher","first-page":"558","DOI":"10.1145\/359545.359563","volume":"21","author":"L. Lamport","year":"1978","unstructured":"Lamport, L.: Time, clocks, and the ordering of events in a distributed system. Communications of the ACM\u00a021(7), 558\u2013565 (1978)","journal-title":"Communications of the ACM"},{"issue":"5","key":"7_CR25","doi-asserted-by":"publisher","first-page":"258","DOI":"10.1145\/543552.512560","volume":"37","author":"J.D. Choi","year":"2002","unstructured":"Choi, J.D., Lee, K., Loginov, A., O\u2019Callahan, R., Sarkar, V., Sridharan, M.: Efficient and precise datarace detection for multithreaded object-oriented programs. ACM SIGPLAN Notices\u00a037(5), 258\u2013269 (2002)","journal-title":"ACM SIGPLAN Notices"},{"doi-asserted-by":"crossref","unstructured":"Cheng, G.I., Feng, M., Leiserson, C.E., Randall, K.H., Stark, A.F.: Detecting data races in Cilk programs that use locks. In: Proceedings of the 10th Annual ACM Symposium on Parallel Algorithms and Architectures, pp. 298\u2013309 (1998)","key":"7_CR26","DOI":"10.1145\/277651.277696"},{"issue":"4","key":"7_CR27","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1145\/265924.265927","volume":"15","author":"S. Savage","year":"1997","unstructured":"Savage, S., Burrows, M., Nelson, G., Sobalvarro, P., Anderson, T.E.: Eraser: A dynamic data race detector for multithreaded programs. ACM Transactions on Computer Systems\u00a015(4), 391\u2013411 (1997)","journal-title":"ACM Transactions on Computer Systems"},{"doi-asserted-by":"crossref","unstructured":"Yu, Y., Rodeheffer, T., Chen, W.: RaceTrack: Efficient detection of data race conditions via adaptive tracking. Technical report, Microsoft Research (April 2005)","key":"7_CR28","DOI":"10.1145\/1095810.1095832"},{"issue":"10","key":"7_CR29","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1145\/966049.781529","volume":"38","author":"E. Pozniansky","year":"2003","unstructured":"Pozniansky, E., Schuster, A.: Efficient on-the-fly data race detection in multithreaded C++ programs. ACM SIGPLAN Notices\u00a038(10), 179\u2013190 (2003)","journal-title":"ACM SIGPLAN Notices"},{"unstructured":"Tsyrklevich, E., Yee, B.: Dynamic detection and prevention of race conditions in file accesses. In: Proceedings of the 12th USENIX Security Symposium (August 2003)","key":"7_CR30"},{"unstructured":"Chamillard, A.T., Clarke, L.A., Avrunin, G.S.: An empirical comparison of static concurrency analysis techniques (July 23, 1996)","key":"7_CR31"},{"doi-asserted-by":"crossref","unstructured":"Visser, W., Havelund, K., Brat, G., Park, S.J.: Model checking programs. In: Proceedings of the 15th IEEE International Conference on Automated Software Engineering (September 2000)","key":"7_CR32","DOI":"10.1109\/ASE.2000.873645"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-70542-0_7.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T05:07:33Z","timestamp":1605762453000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-70542-0_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540705413","9783540705420"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-70542-0_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[]}}