{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T04:51:07Z","timestamp":1755838267026,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,3,26]],"date-time":"2012-03-26T00:00:00Z","timestamp":1332720000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"PoSecCo project","award":["2.17E+11"],"award-info":[{"award-number":["2.17E+11"]}]},{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["FP7\/2007-2013"],"award-info":[{"award-number":["FP7\/2007-2013"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-1116777"],"award-info":[{"award-number":["CNS-1116777"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,3,26]]},"DOI":"10.1145\/2245276.2232004","type":"proceedings-article","created":{"date-parts":[[2012,6,11]],"date-time":"2012-06-11T13:03:31Z","timestamp":1339419811000},"page":"1419-1426","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["An empirical analysis of input validation mechanisms in web applications and languages"],"prefix":"10.1145","author":[{"given":"Theodoor","family":"Scholte","sequence":"first","affiliation":[{"name":"SAP Research Sophia Antipolis, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[{"name":"Northeastern University Boston"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Institute Eurecom Sophia Antipolis, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Northeastern University Boston"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,3,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.22"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772701"},{"key":"e_1_3_2_1_3_1","volume-title":"Exploring the Relationship Between Web Application Development Tools and Security. In USENIX Conference on Web Application Development (WebApps). USENIX Association","author":"Finifter M.","year":"2011","unstructured":"M. Finifter and D. Wagner . Exploring the Relationship Between Web Application Development Tools and Security. In USENIX Conference on Web Application Development (WebApps). USENIX Association , June 2011 . M. Finifter and D. Wagner. Exploring the Relationship Between Web Application Development Tools and Security. In USENIX Conference on Web Application Development (WebApps). USENIX Association, June 2011."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630094"},{"key":"e_1_3_2_1_5_1","unstructured":"Fortify Software. Fortify Software Security Assurance Products. http:\/\/www.fortify.com 2011.  Fortify Software. Fortify Software Security Assurance Products. http:\/\/www.fortify.com 2011."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242654"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11747-3_8"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1141277.1141357"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1255329.1255346"},{"key":"e_1_3_2_1_11_1","first-page":"271","volume-title":"Proceedings of the 14th USENIX Security Symposium","author":"Livshits V. B.","year":"2005","unstructured":"V. B. Livshits and M. S. Lam . Finding Security Errors in Java Programs with Static Analysis . In Proceedings of the 14th USENIX Security Symposium , pages 271 -- 286 , Aug 2005 . V. B. Livshits and M. S. Lam. Finding Security Errors in Java Programs with Static Analysis. In Proceedings of the 14th USENIX Security Symposium, pages 271--286, Aug 2005."},{"key":"e_1_3_2_1_12_1","unstructured":"B. Martin M. Brown A. Paller and D. Kirby. 2011 CWE\/SANS Top 25 Most Dangerous Software Errors. http:\/\/cwe.mitre.org\/top25\/ 2011.  B. Martin M. Brown A. Paller and D. Kirby. 2011 CWE\/SANS Top 25 Most Dangerous Software Errors. http:\/\/cwe.mitre.org\/top25\/ 2011."},{"key":"e_1_3_2_1_13_1","unstructured":"Microsoft Inc. MSDN Code Analysis Team Blog. http:\/\/blogs.msdn.com\/b\/codeanalysis\/ 2010.  Microsoft Inc. MSDN Code Analysis Team Blog. http:\/\/blogs.msdn.com\/b\/codeanalysis\/ 2010."},{"key":"e_1_3_2_1_14_1","unstructured":"MITRE. Common Platform Enumeration (CPE). http:\/\/cpe.mitre.org\/ 2010.  MITRE. Common Platform Enumeration (CPE). http:\/\/cpe.mitre.org\/ 2010."},{"key":"e_1_3_2_1_15_1","unstructured":"MITRE. Common vulnerabilities and exposures (cve). http:\/\/cve.mitre.org\/ 2010.  MITRE. Common vulnerabilities and exposures (cve). http:\/\/cve.mitre.org\/ 2010."},{"key":"e_1_3_2_1_16_1","unstructured":"MITRE. Common weakness enumeration (cwe). http:\/\/cwe.mitre.org\/ 2010.  MITRE. Common weakness enumeration (cwe). http:\/\/cwe.mitre.org\/ 2010."},{"key":"e_1_3_2_1_17_1","unstructured":"National Institute of Standards and Technology. National Vulnerability Database Version 2.2. http:\/\/nvd.nist.gov\/ 2010.  National Institute of Standards and Technology. National Vulnerability Database Version 2.2. http:\/\/nvd.nist.gov\/ 2010."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the ISOC Network and Distributed Systems Symposium","author":"Newsome J.","year":"2005","unstructured":"J. Newsome and D. X. Song . Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software . In Proceedings of the ISOC Network and Distributed Systems Symposium , 2005 . J. Newsome and D. X. Song. Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software. In Proceedings of the ISOC Network and Distributed Systems Symposium, 2005."},{"key":"e_1_3_2_1_19_1","first-page":"295","volume-title":"SEC","author":"Nguyen-Tuong A.","year":"2005","unstructured":"A. Nguyen-Tuong , S. Guarnieri , D. Greene , J. Shirley , and D. Evans . Automatically Hardening Web Applications Using Precise Tainting . In SEC , pages 295 -- 308 , 2005 . A. Nguyen-Tuong, S. Guarnieri, D. Greene, J. Shirley, and D. Evans. Automatically Hardening Web Applications Using Precise Tainting. In SEC, pages 295--308, 2005."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_7"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1855768.1855786"},{"key":"e_1_3_2_1_22_1","unstructured":"SANS Intitute. Information Security Training Certification & Research. http:\/\/www.sans.org\/ 2011.  SANS Intitute. Information Security Training Certification & Research. http:\/\/www.sans.org\/ 2011."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-27576-0_24"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2009.30"},{"key":"e_1_3_2_1_25_1","unstructured":"The Open Web Application Security Project. OWASP - The Open Web Application Security Project. http:\/\/www.owasp.org\/ 2011.  The Open Web Application Security Project. OWASP - The Open Web Application Security Project. http:\/\/www.owasp.org\/ 2011."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653685"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250739"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368088.1368112"},{"key":"e_1_3_2_1_29_1","volume-title":"UC Berkeley","author":"Weinberger J.","year":"2011","unstructured":"J. Weinberger , P. Saxena , D. Akhawe , M. Finifter , R. Shin , and D. Song . An Empirical Analysis of XSS Sanitization in Web Application Frameworks. Technical report , UC Berkeley , 2011 . J. Weinberger, P. Saxena, D. Akhawe, M. Finifter, R. Shin, and D. Song. An Empirical Analysis of XSS Sanitization in Web Application Frameworks. Technical report, UC Berkeley, 2011."},{"key":"e_1_3_2_1_30_1","unstructured":"WhiteHat Security. WhiteHat Security Statistics Report. http:\/\/www.whitehatsec.com 2011.  WhiteHat Security. WhiteHat Security Statistics Report. http:\/\/www.whitehatsec.com 2011."},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 15th USENIX Security Symposium","author":"Xie Y.","year":"2006","unstructured":"Y. Xie and A. Aiken . Static detection of security vulnerabilities in scripting languages . In Proceedings of the 15th USENIX Security Symposium , Vancouver, B.C., Canada , 2006 . USENIX Association. Y. Xie and A. Aiken. Static detection of security vulnerabilities in scripting languages. In Proceedings of the 15th USENIX Security Symposium, Vancouver, B.C., Canada, 2006. USENIX Association."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1367497.1367566"}],"event":{"name":"SAC 2012: ACM Symposium on Applied Computing","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Trento Italy","acronym":"SAC 2012"},"container-title":["Proceedings of the 27th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2245276.2232004","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2245276.2232004","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:43Z","timestamp":1750241203000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2245276.2232004"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,3,26]]},"references-count":32,"alternative-id":["10.1145\/2245276.2232004","10.1145\/2245276"],"URL":"https:\/\/doi.org\/10.1145\/2245276.2232004","relation":{},"subject":[],"published":{"date-parts":[[2012,3,26]]},"assertion":[{"value":"2012-03-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}