{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T05:53:25Z","timestamp":1769925205262,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":23,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,8,29]],"date-time":"2017-08-29T00:00:00Z","timestamp":1503964800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,8,29]]},"DOI":"10.1145\/3098954.3103173","type":"proceedings-article","created":{"date-parts":[[2017,8,10]],"date-time":"2017-08-10T12:12:36Z","timestamp":1502367156000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Source Code Patterns of SQL Injection Vulnerabilities"],"prefix":"10.1145","author":[{"given":"Felix","family":"Schuckert","sequence":"first","affiliation":[{"name":"HTWG Konstanz, Department of Computer Science, Konstanz, Germany, Norwegian University of Science and Technology, Department of Information Security and Communication Technology, Gj\u00f8vik, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[{"name":"Norwegian University of Science and Technology, Department of Information Security and Communication Technology, Gj\u00f8vik, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hanno","family":"Langweg","sequence":"additional","affiliation":[{"name":"HTWG Konstanz, Department of Computer Science, Konstanz, Germany, Norwegian University of Science and Technology, Department of Information Security and Communication Technology, Gj\u00f8vik, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2017. ADOdb. (2017). Retrieved April 27 2017 from https:\/\/github.com\/ADOdb\/ADOdb  2017. ADOdb. (2017). Retrieved April 27 2017 from https:\/\/github.com\/ADOdb\/ADOdb"},{"key":"e_1_3_2_1_2_1","volume-title":"Retrieved","year":"2017"},{"key":"e_1_3_2_1_3_1","volume-title":"Retrieved","year":"2017"},{"key":"e_1_3_2_1_4_1","unstructured":"2017. CVE Details. (2017). Retrieved April 27 2017 from https:\/\/www.cvedetails.com\/  2017. CVE Details. (2017). Retrieved April 27 2017 from https:\/\/www.cvedetails.com\/"},{"key":"e_1_3_2_1_5_1","unstructured":"2017. GitHub. (2017). Retrieved April 27 2017 from https:\/\/github.com\/  2017. GitHub. (2017). Retrieved April 27 2017 from https:\/\/github.com\/"},{"key":"e_1_3_2_1_6_1","volume-title":"Retrieved","year":"2017"},{"key":"e_1_3_2_1_7_1","unstructured":"2017. PHP manual - function.header.php. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/function.header.php  2017. PHP manual - function.header.php. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/function.header.php"},{"key":"e_1_3_2_1_8_1","unstructured":"2017. PHP manual - sprintf. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/function.sprintf.php  2017. PHP manual - sprintf. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/function.sprintf.php"},{"key":"e_1_3_2_1_9_1","unstructured":"2017. PHP manual - string conversion. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/language.types.string.php#language.types.string.conversion  2017. PHP manual - string conversion. (2017). Retrieved April 27 2017 from http:\/\/php.net\/manual\/en\/language.types.string.php#language.types.string.conversion"},{"key":"e_1_3_2_1_10_1","unstructured":"2017. PhpStorm. (2017). Retrieved April 27 2017 from https:\/\/www.jetbrains.com\/phpstorm  2017. PhpStorm. (2017). Retrieved April 27 2017 from https:\/\/www.jetbrains.com\/phpstorm"},{"key":"e_1_3_2_1_11_1","unstructured":"2017. SAMATE - SARD. (2017). Retrieved April 27 2017 from https:\/\/samate.nist.gov\/SARD  2017. SAMATE - SARD. (2017). Retrieved April 27 2017 from https:\/\/samate.nist.gov\/SARD"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133255.1134000"},{"key":"e_1_3_2_1_14_1","unstructured":"Richard Bisbey and Dennis Hollingworth. 1978. Protection analysis: Final report. University of Southern California Information 90291 2223 (1978).  Richard Bisbey and Dennis Hollingworth. 1978. Protection analysis: Final report. University of Southern California Information 90291 2223 (1978)."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings - 2010 International Conference on Intelligent Computing and Integrated Systems, ICISS2010","author":"Hui Zhanwei","year":"2010"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/JCSSE.2011.5930141"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1853919.1853925"},{"key":"e_1_3_2_1_18_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2015.2457411"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Robert C. Seacord and Allen D. Householder. 2005. A Structured Approach to Classifying Security Vulnerabilities. Carnegie-Mellon Univ Pittsburgh Pa Software Engineering Inst January (2005) 1--39.  Robert C. Seacord and Allen D. Householder. 2005. A Structured Approach to Classifying Security Vulnerabilities. Carnegie-Mellon Univ Pittsburgh Pa Software Engineering Inst January (2005) 1--39.","DOI":"10.21236\/ADA430968"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings - International Conference on Software Engineering","author":"Shar Lwin Khin","year":"2013"},{"key":"e_1_3_2_1_22_1","unstructured":"Lwin Khin Shar and Hee Kuan Tan. 2012. Mining Input Sanitization Patterns for Predicting SQL Injection and Cross Site Scripting Vulnerabilities. (2012) 1293--1296.   Lwin Khin Shar and Hee Kuan Tan. 2012. Mining Input Sanitization Patterns for Predicting SQL Injection and Cross Site Scripting Vulnerabilities. (2012) 1293--1296."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2016.43"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985960"}],"event":{"name":"ARES '17: International Conference on Availability, Reliability and Security","location":"Reggio Calabria Italy","acronym":"ARES '17"},"container-title":["Proceedings of the 12th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098954.3103173","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3098954.3103173","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:37:25Z","timestamp":1750217845000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098954.3103173"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,29]]},"references-count":23,"alternative-id":["10.1145\/3098954.3103173","10.1145\/3098954"],"URL":"https:\/\/doi.org\/10.1145\/3098954.3103173","relation":{},"subject":[],"published":{"date-parts":[[2017,8,29]]},"assertion":[{"value":"2017-08-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}