{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T15:33:44Z","timestamp":1772120024539,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":71,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642238215","type":"print"},{"value":"9783642238222","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-23822-2_9","type":"book-chapter","created":{"date-parts":[[2011,9,7]],"date-time":"2011-09-07T14:38:34Z","timestamp":1315406314000},"page":"150-171","source":"Crossref","is-referenced-by-count":53,"title":["A Systematic Analysis of XSS Sanitization in Web Application Frameworks"],"prefix":"10.1007","author":[{"given":"Joel","family":"Weinberger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prateek","family":"Saxena","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Devdatta","family":"Akhawe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthew","family":"Finifter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Richard","family":"Shin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dawn","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"9_CR1","unstructured":"jQuery, http:\/\/jquery.com\/"},{"key":"9_CR2","unstructured":"Aas, G.: CPAN: URI::Escape, http:\/\/search.cpan.org\/~gaas\/URI-1.56\/URI\/Escape.pm"},{"key":"9_CR3","unstructured":"Adsafe : Making javascript safe for advertising, http:\/\/www.adsafe.org\/"},{"key":"9_CR4","unstructured":"How To: Prevent Cross-Site Scripting in ASP.NET, http:\/\/msdn.microsoft.com\/en-us\/library\/ff649310.aspx"},{"key":"9_CR5","unstructured":"Microsoft ASP.NET: Request Validation \u2013 Preventing Script Attacks, http:\/\/www.asp.net\/LEARN\/whitepapers\/request-validation"},{"key":"9_CR6","unstructured":"Athanasopoulos, E., Pappas, V., Krithinakis, A., Ligouras, S., Markatos, E., Karagiannis, T.: xJS: practical XSS prevention for web application development. In: Proceedings of the 2010 USENIX Conference on Web Application Development (2010)"},{"key":"9_CR7","doi-asserted-by":"crossref","unstructured":"Balzarotti, D., Cova, M., Felmetsger, V., Jovanovic, N., Kirda, E., Kruegel, C., Vigna, G.: Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In: Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA (2008)","DOI":"10.1109\/SP.2008.22"},{"key":"9_CR8","doi-asserted-by":"crossref","unstructured":"Bandhakavi, S., King, S.T., Madhusudan, P., Winslett, M.: Vex: Vetting browser extensions for security vulnerabilities (2010)","DOI":"10.1145\/1995376.1995398"},{"key":"9_CR9","unstructured":"Baron, D.: Mozilla\u2019s quirks mode, https:\/\/developer.mozilla.org\/en\/mozilla's_quirks_mode"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Barth, A., Caballero, J., Song, D.: Secure content sniffing for web browsers or how to stop papers from reviewing themselves. In: Proceedings of the 30th IEEE Symposium on Security and Privacy, Oakland, CA (May 2009)","DOI":"10.1109\/SP.2009.3"},{"key":"9_CR11","unstructured":"Barth, A., Felt, A.P., Saxena, P., Boodman, A.: Protecting browsers from extension vulnerabilities (2009)"},{"key":"9_CR12","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1145\/1772690.1772701","volume-title":"Proceedings of the 19th International Conference on World Wide Web, WWW 2010","author":"D. Bates","year":"2010","unstructured":"Bates, D., Barth, A., Jackson, C.: Regular expressions considered harmful in client-side xss filters. In: Proceedings of the 19th International Conference on World Wide Web, WWW 2010, pp. 91\u2013100. ACM, New York (2010)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Bisht, P., Venkatakrishnan, V.: XSS-GUARD: precise dynamic prevention of cross-site scripting attacks. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 23\u201343 (2008)","DOI":"10.1007\/978-3-540-70542-0_2"},{"key":"9_CR14","unstructured":"Google-caja: A source-to-source translator for securing javascript-based web content, http:\/\/code.google.com\/p\/google-caja\/"},{"key":"9_CR15","unstructured":"CakePHP: Sanitize Class Info, http:\/\/api.cakephp.org\/class\/sanitize"},{"key":"9_CR16","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1655121.1655125","volume-title":"Proceedings of the 2009 ACM Workshop on Secure Web Services, SWS 2009","author":"E. Chin","year":"2009","unstructured":"Chin, E., Wagner, D.: Efficient character-level taint tracking for java. In: Proceedings of the 2009 ACM Workshop on Secure Web Services, SWS 2009, pp. 3\u201312. ACM, New York (2009)"},{"key":"9_CR17","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1145\/1294261.1294265","volume-title":"Proceedings of Twenty-First ACM SIGOPS Symposium on Operating Systems Principles","author":"S. Chong","year":"2007","unstructured":"Chong, S., Liu, J., Myers, A.C., Qi, X., Vikram, K., Zheng, L., Zheng, X.: Secure web applications via automatic partitioning. In: Proceedings of Twenty-First ACM SIGOPS Symposium on Operating Systems Principles, pp. 31\u201344. ACM, New York (2007)"},{"key":"9_CR18","unstructured":"ClearSilver: Template Filters, http:\/\/www.clearsilver.net\/docs\/man_filters.hdf"},{"key":"9_CR19","unstructured":"CodeIgniter\/system\/libraries\/Security.php, http:\/\/bitbucket.org\/ellislab\/codeigniter\/src\/tip\/system\/libraries\/Security.php"},{"key":"9_CR20","unstructured":"CodeIgniter User Guide Version 1.7.2: Input Class, http:\/\/codeigniter.com\/user_guide\/libraries\/input.html"},{"key":"9_CR21","unstructured":"Ctemplate: Guide to Using Auto Escape, http:\/\/google-ctemplate.googlecode.com\/svn\/trunk\/doc\/auto_escape.html"},{"key":"9_CR22","unstructured":"django: Built-in template tags and filters, http:\/\/docs.djangoproject.com\/en\/dev\/ref\/templates\/builtins"},{"key":"9_CR23","unstructured":"Django sites : Websites powered by django, http:\/\/www.djangosites.org\/"},{"key":"9_CR24","unstructured":"The Django Book: Security, http:\/\/www.djangobook.com\/en\/2.0\/chapter20\/"},{"key":"9_CR25","unstructured":"Finifter, M., Wagner, D.: Exploring the Relationship Between Web Application Development Tools and Security. In: Proceedings of the 2nd USENIX Conference on Web Application Development. USENIX (June 2011)"},{"key":"9_CR26","unstructured":"Finifter, M., Weinberger, J., Barth, A.: Preventing capability leaks in secure javascript subsets. In: Proc. of Network and Distributed System Security Symposium (2010)"},{"key":"9_CR27","first-page":"561","volume-title":"Proceedings of the 18th International Conference on World Wide Web, WWW 2009","author":"A. Guha","year":"2009","unstructured":"Guha, A., Krishnamurthi, S., Jim, T.: Using static analysis for ajax intrusion detection. In: Proceedings of the 18th International Conference on World Wide Web, WWW 2009, pp. 561\u2013570. ACM, New York (2009)"},{"key":"9_CR28","unstructured":"Google Web Toolkit: Developer\u2019s Guide \u2013 SafeHtml, http:\/\/code.google.com\/webtoolkit\/doc\/latest\/DevGuideSecuritySafeHtml.html"},{"key":"9_CR29","unstructured":"Hansen, R.: XSS cheat sheet (2008)"},{"key":"9_CR30","unstructured":"Hickson, I.: HTML 5 : A vocabulary and associated apis for html and xhtml, http:\/\/www.w3.org\/TR\/html5\/"},{"key":"9_CR31","unstructured":"HTML Purifier Team: Css quoting full disclosure (2010), http:\/\/htmlpurifier.org\/security\/2010\/css-quoting"},{"key":"9_CR32","unstructured":"HTML Purifier : Standards-Compliant HTML Filtering, http:\/\/htmlpurifier.org\/"},{"key":"9_CR33","first-page":"40","volume-title":"Proceedings of the 13th International Conference on World Wide Web, WWW 2004","author":"Y.W. Huang","year":"2004","unstructured":"Huang, Y.W., Yu, F., Hang, C., Tsai, C.H., Lee, D.T., Kuo, S.Y.: Securing web application code by static analysis and runtime protection. In: Proceedings of the 13th International Conference on World Wide Web, WWW 2004, pp. 40\u201352. ACM, New York (2004)"},{"key":"9_CR34","unstructured":"Jean, J.: Facebook CSRF and XSS vulnerabilities: Destructive worms on a social network, http:\/\/seclists.org\/fulldisclosure\/2010\/Oct\/35"},{"key":"9_CR35","unstructured":"JiftyManual, http:\/\/jifty.org\/view\/JiftyManual"},{"key":"9_CR36","doi-asserted-by":"crossref","unstructured":"Jovanovic, N., Kr\u00fcgel, C., Kirda, E.: Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In: IEEE Symposium on Security and Privacy (2006)","DOI":"10.1109\/SP.2006.29"},{"key":"9_CR37","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1145\/1141277.1141357","volume-title":"Proceedings of the 2006 ACM Symposium on Applied Computing","author":"E. Kirda","year":"2006","unstructured":"Kirda, E., Kruegel, C., Vigna, G., Jovanovic, N.: Noxes: a client-side solution for mitigating cross-site scripting attacks. In: Proceedings of the 2006 ACM Symposium on Applied Computing, pp. 330\u2013337. ACM, New York (2006)"},{"key":"9_CR38","unstructured":"KSES Developer Team: Kses php html\/xhtml filter, http:\/\/sourceforge.net\/projects\/kses\/"},{"key":"9_CR39","unstructured":"Livshits, B., Lam, M.S.: Finding security errors in Java programs with static analysis. In: Proceedings of the Usenix Security Symposium (2005)"},{"key":"9_CR40","unstructured":"Livshits, B., Martin, M., Lam, M.S.: SecuriFly: Runtime protection and recovery from Web application vulnerabilities. Tech. rep., Stanford University (September 2006)"},{"key":"9_CR41","unstructured":"Martin, M., Lam, M.S.: Automatic generation of XSS and SQL injection attacks with goal-directed model checking. In: 17th USENIX Security Symposium (2008)"},{"key":"9_CR42","unstructured":"The Mason Book: Escaping Substitutions, http:\/\/www.masonbook.com\/book\/chapter-2.mhtml"},{"key":"9_CR43","unstructured":"Nadji, Y., Saxena, P., Song, D.: Document structure integrity: A robust basis for cross-site scripting defense. In: NDSS (2009)"},{"key":"9_CR44","doi-asserted-by":"crossref","unstructured":"Nguyen-Tuong, A., Guarnieri, S., Greene, D., Shirley, J., Evans, D.: Automatically hardening web applications using precise tainting. In: 20th IFIP International Information Security Conference (2005)","DOI":"10.21236\/ADA436667"},{"key":"9_CR45","unstructured":"XSS Prevention Cheat Sheet, http:\/\/www.owasp.org\/index.php\/XSS_Cross_Site_Scripting_Prevention_Cheat_Sheet"},{"key":"9_CR46","unstructured":"Pullicino, J.: Google XSS Flaw in Website Optimizer Explained (December 2010), http:\/\/www.acunetix.com\/blog\/web-security-zone\/articles\/google-xss-website-optimizer-scripts\/"},{"key":"9_CR47","first-page":"283","volume-title":"Proceedings of the 18th Conference on USENIX Security Symposium, SSYM 2009","author":"W. Robertson","year":"2009","unstructured":"Robertson, W., Vigna, G.: Static enforcement of web application integrity through strong typing. In: Proceedings of the 18th Conference on USENIX Security Symposium, SSYM 2009, pp. 283\u2013298. USENIX Association, Berkeley (2009)"},{"key":"9_CR48","unstructured":"Ruby on Rails Security Guide, http:\/\/guides.rubyonrails.org\/security.html"},{"key":"9_CR49","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1109\/SP.2010.38","volume-title":"Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010","author":"P. Saxena","year":"2010","unstructured":"Saxena, P., Akhawe, D., Hanna, S., Mao, F., McCamant, S., Song, D.: A symbolic execution framework for javascript. In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 513\u2013528. IEEE Computer Society, Washington, DC, USA (2010)"},{"key":"9_CR50","unstructured":"Saxena, P., Hanna, S., Poosankam, P., Song, D.: FLAX: Systematic discovery of client-side validation vulnerabilities in rich web applications. In: 17th Annual Network & Distributed System Security Symposium NDSS (2010)"},{"key":"9_CR51","doi-asserted-by":"crossref","unstructured":"Saxena, P., Molnar, D., Livshits, B.: Scriptgard: Preventing script injection attacks in legacy web applications with automatic sanitization. Tech. rep., Microsoft Research (September 2010)","DOI":"10.1145\/2046707.2046776"},{"key":"9_CR52","unstructured":"Schmidt, B.: Google Analytics XSS Vulnerability, http:\/\/spareclockcycles.org\/2011\/02\/03\/google-analytics-xss-vulnerability\/"},{"key":"9_CR53","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1109\/SP.2010.26","volume-title":"Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010","author":"E.J. Schwartz","year":"2010","unstructured":"Schwartz, E.J., Avgerinos, T., Brumley, D.: All you ever wanted to know about dynamic taint analysis and forward symbolic execution (but might have been afraid to ask). In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 317\u2013331. IEEE Computer Society, Washington, DC, USA (2010)"},{"key":"9_CR54","unstructured":"Seo, J., Lam, M.S.: Invisitype: Object-oriented security policies (2010)"},{"key":"9_CR55","unstructured":"Smarty Template Engine: escape, http:\/\/www.smarty.net\/manual\/en\/language.modifier.escape.php"},{"key":"9_CR56","unstructured":"Stamm, S.: Content security policy (2009), https:\/\/wiki.mozilla.org\/Security\/CSP\/Spec"},{"key":"9_CR57","doi-asserted-by":"crossref","unstructured":"Swamy, N., Corcoran, B., Hicks, M.: Fable: A language for enforcing user-defined security policies. In: Proceedings of the IEEE Symposium on Security and Privacy (May 2008)","DOI":"10.1109\/SP.2008.29"},{"key":"9_CR58","unstructured":"Template::Manual::Filters, http:\/\/template-toolkit.org\/docs\/manual\/Filters.html"},{"key":"9_CR59","unstructured":"Mike, T.L., Venkatakrishnan, V.N.: BluePrint: Robust Prevention of Cross-site Scripting Attacks for Existing Browsers. In: Proceedings of the IEEE Symposium on Security and Privacy (2009)"},{"key":"9_CR60","unstructured":"TwitPwn: DOM based XSS in Twitterfall (2009), http:\/\/www.twitpwn.com\/2009\/07\/motb-08-dom-based-xss-in-twitterfall.html"},{"key":"9_CR61","unstructured":"Twitter: All about the \u201conMouseOver\u201d incident, http:\/\/blog.twitter.com\/2010\/09\/all-about-onmouseover-incident.html"},{"key":"9_CR62","unstructured":"UTF-7 XSS Cheat Sheet, http:\/\/openmya.hacker.jp\/hasegawa\/security\/utf7cs.html"},{"key":"9_CR63","unstructured":"Venema, W.: Taint support for PHP (2007), ftp:\/\/ftp.porcupine.org\/pub\/php\/php-5.2.3-taint-20071103.README.html"},{"key":"9_CR64","unstructured":"Vogt, P., Nentwich, F., Jovanovic, N., Kirda, E., Kruegel, C., Vigna, G.: Cross site scripting prevention with dynamic data tainting and static analysis. In: Proceeding of the Network and Distributed System Security Symposium (NDSS), vol.\u00a042. Citeseer (2007)"},{"key":"9_CR65","doi-asserted-by":"crossref","unstructured":"Weinberger, J., Saxena, P., Akhawe, D., Finifter, M., Shin, R., Song, D.: An empirical analysis of xss sanitization in web application frameworks. Tech. Rep. UCB\/EECS-2011-11, EECS Department, University of California, Berkeley (February 2011)","DOI":"10.1007\/978-3-642-23822-2_9"},{"key":"9_CR66","unstructured":"Xie, Y., Aiken, A.: Static detection of security vulnerabilities in scripting languages. In: Proceedings of the Usenix Security Symposium (2006)"},{"key":"9_CR67","unstructured":"xssterminate, http:\/\/code.google.com\/p\/xssterminate\/"},{"key":"9_CR68","doi-asserted-by":"crossref","unstructured":"Xu, W., Bhatkar, S., Sekar, R.: Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In: Proceedings of the 15th USENIX Security Symposium, pp. 121\u2013136 (2006)","DOI":"10.1109\/SP.2006.12"},{"key":"9_CR69","unstructured":"Yii Framework: Security, http:\/\/www.yiiframework.com\/doc\/guide\/1.1\/en\/topics.security"},{"key":"9_CR70","unstructured":"Zalewski, M.: Browser security handbook. Google Code (2010), http:\/\/code.google.com\/p\/browsersec\/wiki\/Part1"},{"key":"9_CR71","unstructured":"Zend Framework: Zend_Filter, http:\/\/framework.zend.com\/manual\/en\/zend.filter.set.html"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2011"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-23822-2_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,9]],"date-time":"2025-03-09T23:21:20Z","timestamp":1741562480000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-23822-2_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642238215","9783642238222"],"references-count":71,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-23822-2_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011]]}}}