{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T22:55:22Z","timestamp":1762210522758},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540729112"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-72912-9_13","type":"book-chapter","created":{"date-parts":[[2007,9,12]],"date-time":"2007-09-12T09:20:17Z","timestamp":1189588817000},"page":"363-394","source":"Crossref","is-referenced-by-count":9,"title":["Vulnerability Analysis of Web-based Applications"],"prefix":"10.1007","author":[{"given":"Marco","family":"Cova","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Viktoria","family":"Felmetsger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"13_CR1","unstructured":"C. Anley. Advanced SQL Injection in SQL Server Applications. Technical report, Next Generation Security Software, Ltd, 2002."},{"key":"13_CR2","unstructured":"J. Bercegay. Double Choco Latte Vulnerabilities. http:\/\/www.gulftech.org\/?node=research&article_id=00066-04082005, April 2005."},{"key":"13_CR3","unstructured":"M. Brown. FastCGI Specification. Technical report, Open Market, Inc., 1996."},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"A. Christensen, A. M\u00f8ller, and M. Schwartzbach. Precise Analysis of String Expressions. In Proceedings of the 10th International Static Analysis Symposium (SAS\u201903), pp. 1\u201318, May 2003.","DOI":"10.1007\/3-540-44898-5_1"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"R. Fielding, J. Gettys, J. Mogul, H. Frystyk, L. Masinter, P. Leach, and T. Berners-Lee. Hypertext Transfer Protocol \u2013 HTTP\/1.1. RFC 2616 (Draft Standard), June 1999. Updated by RFC 2817.","DOI":"10.17487\/rfc2616"},{"key":"13_CR6","unstructured":"K. Fu, E. Sit, K. Smith, and N. Feamster. Dos and Don\u2019ts of Client Authentication on the Web. In Proceedings of the USENIX Security Symposium, Washington, DC, August 2001."},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"C. Gould, Z. Su, and P. Devanbu. Static Checking of Dynamically Generated Queries in Database Applications. In Proceedings of the 26th International Conference of Software Engineering (ICSE\u201904), pages 645\u2013654, September 2004.","DOI":"10.1109\/ICSE.2004.1317486"},{"key":"13_CR8","doi-asserted-by":"crossref","unstructured":"V. Haldar, D. Chandra, and M. Franz. Dynamic Taint Propagation for Java. In Proceedings of the 21st Annual Computer Security Applications Conference (ACSAC\u201905), pages 303\u2013311, December 2005.","DOI":"10.1109\/CSAC.2005.21"},{"key":"13_CR9","doi-asserted-by":"crossref","unstructured":"W. Halfond and A. Orso. AMNESIA: Analysis and Monitoring for NEutralizing SQL-Injection Attacks. In Proceedings of the International Conference on Automated Software Engineering (ASE\u201905), pp. 174\u2013183, November 2005.","DOI":"10.1145\/1101908.1101935"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D. Lee, and S.-Y. Kuo. Securing Web Application Code by Static Analysis and Runtime Protection. In Proceedings of the 12th International World Wide Web Conference (WWW\u201904), pp. 40\u201352, May 2004.","DOI":"10.1145\/988672.988679"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"N. Jovanovic. txtForum: Script Injection Vulnerability. http:\/\/www.seclab.tuwien.ac.at\/advisories\/TUVSA-0603-004.txt, March 2006.","DOI":"10.1088\/1126-6708\/2006\/11\/004"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"N. Jovanovic, C. Kruegel, and E. Kirda. Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In Proceedings of the IEEE Symposium on Security and Privacy, May 2006.","DOI":"10.1109\/SP.2006.29"},{"key":"13_CR13","doi-asserted-by":"crossref","unstructured":"N. Jovanovic, C. Kruegel, and E. Kirda. Precise Alias Analysis for Static Detection of Web Application Vulnerabilities. In Proceedings of the ACM SIGPLAN Workshop on Programming Languages and Analysis for Security (PLAS\u201906), June 2006.","DOI":"10.1145\/1134744.1134751"},{"key":"13_CR14","unstructured":"A. Klein. Cross Site Scripting Explained. Technical report, Sanctum Inc., 2002."},{"key":"13_CR15","unstructured":"A. Klein. \u201cDivide and Conquer\u201d. HTTP Response Splitting, Web Cache Poisoning Attacks, and Related Topics. Technical report, Sanctum, Inc., 2004."},{"key":"13_CR16","unstructured":"A. Klein. DOM Based Cross Site Scripting or XSS of the Third Kind. Technical report, Web Application Security Consortium, 2005."},{"key":"13_CR17","unstructured":"M. Kol\u0161ek. Session Fixation Vulnerability in Web-based Applications. Technical report, ACROS Security, 2002."},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"C. Kruegel and G. Vigna. Anomaly Detection of Web-based Attacks. In Proceedings of the 10th ACM Conference on Computer and Communication Security (CCS\u201903), pp. 251\u2013261, October 2003.","DOI":"10.1145\/948109.948144"},{"issue":"5","key":"13_CR19","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1016\/j.comnet.2005.01.009","volume":"48","author":"C. Kruegel","year":"2005","unstructured":"C. Kruegel, G. Vigna, and W. Robertson. A Multi-model Approach to the Detection of Web-based Attacks. Computer Networks, 48(5):717\u2013738, August 2005.","journal-title":"Computer Networks"},{"key":"13_CR20","unstructured":"C. Linhart, A. Klein, R. Heled, and S. Orrin. HTTP Request Smuggling. Technical report, Watchfire Corporation, 2005."},{"key":"13_CR21","unstructured":"V. Livshits and M. Lam. Finding Security Vulnerabilities in Java Applications with Static Analysis. In Proceedings of the 14th USENIX Security Symposium (USENIX\u201905), pp. 271\u2013286, August 2005."},{"key":"13_CR22","doi-asserted-by":"crossref","unstructured":"Y. Minamide. Static Approximation of Dynamically Generated Web Pages. In Proceedings of the 14th International World Wide Web Conference (WWW\u201905), pp. 432\u2013441, May 2005.","DOI":"10.1145\/1060745.1060809"},{"key":"13_CR23","unstructured":"NCSA Software Development Group. The Common Gateway Interface. http:\/\/hoohoo.ncsa.uiuc.edu\/cgi\/."},{"key":"13_CR24","unstructured":"Netcraft. PHP Usage Stats. http:\/\/www.php.net\/usage.php, April 2006."},{"key":"13_CR25","doi-asserted-by":"crossref","unstructured":"A. Nguyen-Tuong, S. Guarnieri, D. Greene, and D. Evans. Automatically Hardening Web Applications Using Precise Tainting. In Proceedings of the 20th International Information Security Conference (SEC\u201905), pp. 372\u2013382, May 2005.","DOI":"10.1007\/0-387-25660-1_20"},{"key":"13_CR26","unstructured":"OWASP. WebGoat. http:\/\/wwwo.wasp.org\/software\/webgoat.html, 2006."},{"key":"13_CR27","unstructured":"Perl. Perl security. http:\/\/perldoc.perl.org\/perlsec.html."},{"key":"13_CR28","unstructured":"rgod. PHP Advanced Transfer Manager v1.30 underlying system disclosure \/ remote command execution \/ cross site scripting. http:\/\/retrogod.altervista.org\/phpatm130.html, 2005."},{"key":"13_CR29","unstructured":"Security Space. Apache Module Report. http:\/\/www.securityspace.com\/s_survey\/data\/man.200603\/apachemods.html, April 2006."},{"key":"13_CR30","unstructured":"K. Spett. Blind SQL Injection. Technical report, SPI Dynamics, 2003."},{"key":"13_CR31","doi-asserted-by":"crossref","unstructured":"Z. Su and G. Wassermann. The Essence of Command Injection Attacks in Web Applications. In Proceedings of the 33rd Annual Symposium on Principles of Programming Languages (POPL\u201906), pp. 372\u2013382, 2006.","DOI":"10.1145\/1111037.1111070"},{"key":"13_CR32","unstructured":"Sun. JavaServer Pages. http:\/\/java.sun.com\/products\/jsp\/."},{"key":"13_CR33","unstructured":"Symantec Inc. Symantec Internet Security Threat Report: Vol. VIII. Technical report, Symantec Inc., September 2005."},{"key":"13_CR34","unstructured":"TIOBE Software. TIOBE Programming Community Index for April 2006. http:\/\/www.tiobe.com\/index.htm?tiobe_index, April 2006."},{"key":"13_CR35","doi-asserted-by":"crossref","unstructured":"D. Wagner and P. Soto. Mimicry Attacks on Host-Based Intrusion Detection Systems. In Proceedings of the ACM Conference on Computer and Communications Security, pp. 255\u2013264, Washington DC, November 2002.","DOI":"10.1145\/586110.586145"},{"key":"13_CR36","doi-asserted-by":"crossref","unstructured":"J. Whaley and M. Lam. Cloning-Based Context-Sensitive Pointer Alias Analysis Using Binary Decision Diagrams. In Proceedings of the Conference on Programming Language Design and Implementation (PLDI\u201904), pp. 131\u2013144, June 2004.","DOI":"10.1145\/996841.996859"},{"key":"13_CR37","unstructured":"Y. Xie and A. Aiken. Static Detection of Security Vulnerabilities in Scripting Languages. In Proceedings of the 15th USENIX Security Symposium (USENIX\u201906), August 2006."}],"container-title":["Test and Analysis of Web Services"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-72912-9_13.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,14]],"date-time":"2023-05-14T03:52:21Z","timestamp":1684036341000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-72912-9_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540729112"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-72912-9_13","relation":{},"subject":[]}}