{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T05:01:22Z","timestamp":1768971682628,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":19,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,8,12]],"date-time":"2019-08-12T00:00:00Z","timestamp":1565568000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,8,12]]},"DOI":"10.1145\/3338906.3341178","type":"proceedings-article","created":{"date-parts":[[2019,8,9]],"date-time":"2019-08-09T12:21:03Z","timestamp":1565353263000},"page":"1090-1094","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["JCOMIX: a search-based tool to detect XML injection vulnerabilities in web applications"],"prefix":"10.1145","author":[{"given":"Dimitri Michel","family":"Stallenberg","sequence":"first","affiliation":[{"name":"Delft University of Technology, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Annibale","family":"Panichella","sequence":"additional","affiliation":[{"name":"Delft University of Technology, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,8,12]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"{n.d.}. SmartBear ReadyAPI. http:\/\/smartbear.com\/product\/ready-api\/overview\/. Accessed: 2016-04-26.  {n.d.}. SmartBear ReadyAPI. http:\/\/smartbear.com\/product\/ready-api\/overview\/. Accessed: 2016-04-26."},{"key":"e_1_3_2_1_2_1","unstructured":"{n.d.}. WSFuzzer Tool. https:\/\/www.owasp.org\/index.php\/Category:OWASP_ WSFuzzer_Project. Accessed: 2016-04-26.  {n.d.}. WSFuzzer Tool. https:\/\/www.owasp.org\/index.php\/Category:OWASP_ WSFuzzer_Project. Accessed: 2016-04-26."},{"key":"e_1_3_2_1_3_1","volume-title":"XML Vulnerabilities Introduction"},{"key":"e_1_3_2_1_4_1","volume-title":"Many Independent Objective (MIO) Algorithm for Test Suite Generation. In International Symposium on Search Based Software Engineering (SSBSE).","author":"Arcuri Andrea","year":"2017"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/4236.991449"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cor.2007.01.013"},{"key":"e_1_3_2_1_7_1","unstructured":"Giovanni Grano Timofey V Titov Sebastiano Panichella and Harald C Gall. {n.d.}. Branch coverage prediction in automated testing. Journal of Software: Evolution and Process ({n. d.}) e2158.  Giovanni Grano Timofey V Titov Sebastiano Panichella and Harald C Gall. {n.d.}. Branch coverage prediction in automated testing. Journal of Software: Evolution and Process ({n. d.}) e2158."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the 10th IEEE International Conference on Software Testing, Verification and Validation (ICST","author":"Jan Sadeeq","year":"2017"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931042"},{"key":"e_1_3_2_1_10_1","first-page":"1","article-title":"Automatic Generation of Tests to Exploit XML Injection Vulnerabilities in Web Applications","volume":"99","author":"Jan S.","year":"2017","journal-title":"IEEE Transactions on Software Engineering PP"},{"key":"e_1_3_2_1_11_1","volume-title":"Searchbased multi-vulnerability testing of XML injections in web applications. Empirical Software Engineering (13","author":"Jan Sadeeq","year":"2019"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00450-009-0092-6"},{"key":"e_1_3_2_1_13_1","volume-title":"Building Microservices. \" O\u2019Reilly Media","author":"Newman Sam"},{"key":"e_1_3_2_1_14_1","volume-title":"Automated Test Case Generation as a Many-Objective Optimisation Problem with Dynamic Selection of the Targets","author":"Panichella Annibale","year":"2017"},{"key":"e_1_3_2_1_15_1","volume-title":"Verification and Validation (ICST), 2015 IEEE 8th International Conference on. IEEE, 1\u201310","author":"Panichella Annibale","year":"2015"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","volume-title":"Core Software Security: Security at the Source","author":"Ransome James","DOI":"10.1201\/b16134"},{"key":"e_1_3_2_1_17_1","volume-title":"Microservices: Building Scalable Software","author":"Sharma S.","year":"2017"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2593833.2593835"},{"key":"e_1_3_2_1_19_1","unstructured":"Jeff Williams and Dave Wichers. 2013. OWASP Top 10 The Ten Most Critical Web Application Security Risks. Technical Report. The Open Web Application Security Project. Abstract 1 Introduction 2 The Tool 2.1 Test Objective Generation (TOG) 2.2 Penetration Testing Generation (PTG) 3 Evaluation 4 Conclusions References  Jeff Williams and Dave Wichers. 2013. OWASP Top 10 The Ten Most Critical Web Application Security Risks. Technical Report. The Open Web Application Security Project. Abstract 1 Introduction 2 The Tool 2.1 Test Objective Generation (TOG) 2.2 Penetration Testing Generation (PTG) 3 Evaluation 4 Conclusions References"}],"event":{"name":"ESEC\/FSE '19: 27th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","location":"Tallinn Estonia","acronym":"ESEC\/FSE '19","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3338906.3341178","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3338906.3341178","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:26:21Z","timestamp":1750206381000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3338906.3341178"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,8,12]]},"references-count":19,"alternative-id":["10.1145\/3338906.3341178","10.1145\/3338906"],"URL":"https:\/\/doi.org\/10.1145\/3338906.3341178","relation":{},"subject":[],"published":{"date-parts":[[2019,8,12]]},"assertion":[{"value":"2019-08-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}