{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:51:55Z","timestamp":1750308715930,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":27,"publisher":"ACM","license":[{"start":{"date-parts":[[2013,3,18]],"date-time":"2013-03-18T00:00:00Z","timestamp":1363564800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2013,3,18]]},"DOI":"10.1145\/2480362.2480699","type":"proceedings-article","created":{"date-parts":[[2013,5,1]],"date-time":"2013-05-01T19:47:45Z","timestamp":1367437665000},"page":"1792-1799","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["EARs in the wild"],"prefix":"10.1145","author":[{"given":"Pierre","family":"Payet","sequence":"first","affiliation":[{"name":"Ecole Superieure d'Informatique Electronique, Automatique, Paris"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adam","family":"Doup\u00e9","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,3,18]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2009.80"},{"volume-title":"E.: Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications. In: Proceedings of the 18th Network and Distributed System Security Symposium (2011)","author":"Balduzzi M.","key":"e_1_3_2_1_2_1"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315250"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.27"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866373"},{"key":"e_1_3_2_1_6_1","unstructured":"Christey S. Martin R. A.: Vulnerability Type Distribution in CVE. Tech. rep. MITRE Corporation (May 2007)  Christey S. Martin R. A.: Vulnerability Type Distribution in CVE. Tech. rep. MITRE Corporation (May 2007)"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2005.844059"},{"key":"e_1_3_2_1_8_1","volume-title":"G.: Swaddler: An Approach for the Anomaly-based Detection of State Violations in Web Applications. In: Proceedings of the 10th international conference on Recent advances in intrusion detection.","volume":"4637","author":"Cova M.","year":"2007"},{"volume-title":"Proceedings of the Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA). Bonn, Germany (July 2010)","author":"Doup\u00e9 A.","key":"e_1_3_2_1_9_1"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046736"},{"volume-title":"G.: Toward Automated Detection of Logic Vulnerabilities in Web Applications. In: Proceedings of the USENIX Security Symposium. Washington, DC (August 2010)","author":"Felmetsger V.","key":"e_1_3_2_1_11_1"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Fielding R. Gettys J. Mogul J. Frystyk H. Masinter L. Leach P. Berners-Lee T.: Hypertext Transfer Protocol -- HTTP\/1.1 (June 1999) http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec10.html   Fielding R. Gettys J. Mogul J. Frystyk H. Masinter L. Leach P. Berners-Lee T.: Hypertext Transfer Protocol -- HTTP\/1.1 (June 1999) http:\/\/www.w3.org\/Protocols\/rfc2616\/rfc2616-sec10.html","DOI":"10.17487\/rfc2616"},{"key":"e_1_3_2_1_13_1","volume-title":"Symantec Corp (April","volume":"16","author":"Fossi M.","year":"2011"},{"key":"e_1_3_2_1_14_1","unstructured":"Grossman J.: Challenges of Automated Web Application Scanning. Blackhat Windows 2004 (2004)  Grossman J.: Challenges of Automated Web Application Scanning. Blackhat Windows 2004 (2004)"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2009.26"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/775152.775174"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988679"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134744.1134751"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1135777.1135817"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076767"},{"key":"e_1_3_2_1_22_1","volume-title":"M.: Finding Security Vulnerabilities in Java Applications with Static Analysis. In: Proceedings of the 14th conference on USENIX Security Symposium -","volume":"14","author":"Livshits B.","year":"2005"},{"volume-title":"Z.: Static Detection of Access Control Vulnerabilities in Web Applications. In: Proceedings of the 20th USENIX conference on Security. pp. 11--11. SEC'11, USENIX Association","year":"2011","author":"Sun F.","key":"e_1_3_2_1_23_1"},{"key":"e_1_3_2_1_24_1","unstructured":"Suto L.: Analyzing the Accuracy and Time Costs of Web Application Security Scanners (2010)  Suto L.: Analyzing the Accuracy and Time Costs of Web Application Security Scanners (2010)"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2009.5270294"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.26"},{"key":"e_1_3_2_1_27_1","unstructured":"Williams J. Wichers D.: Owasp top 10 - 2010 the ten most critical web application security risks. Tech. rep. The OWASP Community (2010)  Williams J. Wichers D.: Owasp top 10 - 2010 the ten most critical web application security risks. Tech. rep. The OWASP Community (2010)"}],"event":{"name":"SAC '13: SAC '13","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Coimbra Portugal","acronym":"SAC '13"},"container-title":["Proceedings of the 28th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2480362.2480699","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2480362.2480699","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:14:24Z","timestamp":1750277664000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2480362.2480699"}},"subtitle":["large-scale analysis of execution after redirect vulnerabilities"],"short-title":[],"issued":{"date-parts":[[2013,3,18]]},"references-count":27,"alternative-id":["10.1145\/2480362.2480699","10.1145\/2480362"],"URL":"https:\/\/doi.org\/10.1145\/2480362.2480699","relation":{},"subject":[],"published":{"date-parts":[[2013,3,18]]},"assertion":[{"value":"2013-03-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}