{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T03:35:38Z","timestamp":1782876938478,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":76,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T00:00:00Z","timestamp":1593216000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100007515","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1844880, CCF-1763822"],"award-info":[{"award-number":["CNS-1844880, CCF-1763822"]}],"id":[{"id":"10.13039\/100007515","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","award":["H98230-18-D-008"],"award-info":[{"award-number":["H98230-18-D-008"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,27]]},"DOI":"10.1145\/3377811.3380326","type":"proceedings-article","created":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T18:25:38Z","timestamp":1601576738000},"page":"284-296","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Revealing injection vulnerabilities by leveraging existing tests"],"prefix":"10.1145","author":[{"given":"Katherine","family":"Hough","sequence":"first","affiliation":[{"name":"George Mason University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gebrehiwet","family":"Welearegai","sequence":"additional","affiliation":[{"name":"University of Potsdam, Potsdam, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Hammer","sequence":"additional","affiliation":[{"name":"University of Potsdam, Potsdam, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan","family":"Bell","sequence":"additional","affiliation":[{"name":"George Mason University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2771783.2771786"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 27th USENIX Conference on Security Symposium (SEC'18)","author":"Alhuzali Abeer","unstructured":"Abeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, and V. N. Venkatakrishnan. 2018. NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications. In Proceedings of the 27th USENIX Conference on Security Symposium (SEC'18). USENIX Association, Berkeley, CA, USA, 377--392. http:\/\/dl.acm.org\/citation.cfm?id=3277203.3277232"},{"key":"e_1_3_2_1_3_1","unstructured":"Apache Foundation. 2019. Apache Struts. https:\/\/struts.apache.org."},{"key":"e_1_3_2_1_4_1","unstructured":"Apache Foundation. 2019. Apache Struts Release History. https:\/\/struts.apache.org\/releases.html."},{"key":"e_1_3_2_1_5_1","unstructured":"Apache Foundation. 2019. Apache Tomcat. https:\/\/tomcat.apache.org."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2610384.2610403"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660193.2660212"},{"key":"e_1_3_2_1_9_1","volume-title":"Ben Chelf, Andy Chou, Bryan Fulton, Seth Hallem, Charles Henri-Gros, Asya Kamsky, Scott McPeak, and Dawson Engler.","author":"Bessey Al","year":"2010","unstructured":"Al Bessey, Ken Block, Ben Chelf, Andy Chou, Bryan Fulton, Seth Hallem, Charles Henri-Gros, Asya Kamsky, Scott McPeak, and Dawson Engler. 2010. A few billion lines of code later: using static analysis to find bugs in the real world. Commun. ACM 53 (February 2010), 66--75. Issue 2."},{"key":"e_1_3_2_1_10_1","unstructured":"Steve Bousquet. 2016. Criminal charges filed in hacking of Florida elections websites. http:\/\/www.miamiherald.com\/news\/politics-government\/article75670177.html."},{"key":"e_1_3_2_1_11_1","unstructured":"Shay Chen. 2014. The Web Application Vulnerability Scanner Evaluation Project. https:\/\/code.google.com\/archive\/p\/wavsep\/."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2006.158"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655121.1655125"},{"key":"e_1_3_2_1_14_1","unstructured":"Al Daniel. 2019. cloc: Count Lines of Code. https:\/\/github.com\/AlDanial\/cloc."},{"key":"e_1_3_2_1_15_1","volume-title":"TaintDroid: An Information-flow Tracking System for Realtime Privacy Monitoring on Smartphones. In OSDI'10","author":"Enck William","year":"1924","unstructured":"William Enck, Peter Gilbert, Byung-Gon Chun, Landon P. Cox, Jaeyeon Jung, Patrick McDaniel, and Anmol N. Sheth. 2010. TaintDroid: An Information-flow Tracking System for Realtime Privacy Monitoring on Smartphones. In OSDI'10. USENIX Association, Berkeley, CA, USA, 6. http:\/\/dl.acm.org\/citation.cfm?id=1924943.1924971"},{"key":"e_1_3_2_1_16_1","unstructured":"Exploit Database. 2019. Offensive Security's Exploit Database Archive. https:\/\/www.exploit-db.com."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"e_1_3_2_1_18_1","unstructured":"Jeff Goldman. 2016. Researchers Find Russian Hacker Selling Access to U.S. Election Assistance Commission. https:\/\/www.esecurityplanet.com\/hackers\/researchers-find-russian-hacker-selling-access-to-u.s.-election-assistance-commission.html."},{"key":"e_1_3_2_1_19_1","unstructured":"Google. 2019. Error-Prone: Catch Common Java Mistakes as Compile-Time Errors. https:\/\/github.com\/google\/error-prone."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.21"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1181775.1181797"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183377.3183393"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-C.2017.14"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"Katherine Hough Gebrehiwet Welearegai Christian Hammer and Jonathan Bell. 2020. Revealing Injection Vulnerabilities by Leveraging Existing Tests (Artifact). (2020). 10.6084\/m9.figshare.11592033","DOI":"10.6084\/m9.figshare.11592033"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Katherine Hough Gebrehiwet Welearegai Christian Hammer and Jonathan Bell. 2020. Revealing Injection Vulnerabilities by Leveraging Existing Tests (GitHub). https:\/\/github.com\/gmu-swe\/rivulet.","DOI":"10.1145\/3377811.3380326"},{"key":"e_1_3_2_1_26_1","unstructured":"iTrust Team. 2019. iTrust - GitHub. https:\/\/github.com\/ncsu-csc326\/iTrust."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931042"},{"key":"e_1_3_2_1_28_1","unstructured":"Jenkins Project Developers. 2019. Jenkins. https:\/\/jenkins.io."},{"key":"e_1_3_2_1_29_1","unstructured":"Jonathan Hedley. 2019. jsoup: Java HTML Parser. https:\/\/jsoup.org\/."},{"key":"e_1_3_2_1_30_1","unstructured":"JSqlParser Project Authors. 2019. JSqlParser. http:\/\/jsqlparser.sourceforge.net\/."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151042"},{"key":"e_1_3_2_1_32_1","volume-title":"ICSE 2009, Proceedings of the 31st International Conference on Software Engineering","author":"Kie\u017cun Adam","unstructured":"Adam Kie\u017cun, Philip J. Guo, Karthick Jayaraman, and Michael D. Ernst. 2009. Automatic creation of SQL injection and cross-site scripting attacks. In ICSE 2009, Proceedings of the 31st International Conference on Software Engineering. Vancouver, BC, Canada, 199--209."},{"key":"e_1_3_2_1_33_1","unstructured":"Tracy Kitten. 2013. Card Fraud Scheme: The Breached Victims. http:\/\/www.bankinfosecurity.com\/card-fraud-scheme-breached-victims-a-5941."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516703"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the Workshop on Defining the State of the Art in Software Security Tools.","author":"Livshits Ben","year":"2005","unstructured":"Ben Livshits. 2005. Defining a Set of Common Benchmarks for Web Application Security. In Proceedings of the Workshop on Defining the State of the Art in Software Security Tools."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2429069.2429115"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1082983.1083216"},{"key":"e_1_3_2_1_39_1","unstructured":"Rick Miller. 2016. \"Foreign\" hack attack on state voter registration site. http:\/\/capitolfax.com\/2016\/07\/21\/foreign-hack-attack-on-state-voter-registration-site\/."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2017.46"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC2965"},{"key":"e_1_3_2_1_42_1","unstructured":"National Institute of Standards and Technology. 2017. Juliet Test Suite for Java. https:\/\/samate.nist.gov\/SRD\/testsuite.php."},{"key":"e_1_3_2_1_43_1","unstructured":"National Vulnerability Database. 2017. CVE-2017-5638 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5638."},{"key":"e_1_3_2_1_44_1","unstructured":"National Vulnerability Database. 2019. National Vulnerability Database search for \"execute arbitrary commands\". https:\/\/nvd.nist.gov\/vuln\/search\/results?form_type=Advanced&results_type=overview&query=execute+arbitrary+commands&search_type=all."},{"key":"e_1_3_2_1_45_1","unstructured":"University of Maryland. 2019. FindBugs - Find Bugs in Java Programs. http:\/\/findbugs.sourceforge.net."},{"key":"e_1_3_2_1_46_1","unstructured":"Open Web Application Security Project. 2017. OWASP Top 10 - 2017 The Ten Most Critical Web Application Security Risks. https:\/\/www.owasp.org\/index.php\/Top_10-2017_Top_10."},{"key":"e_1_3_2_1_47_1","unstructured":"Open Web Application Security Project. 2019. Expression Language Injection. https:\/\/www.owasp.org\/index.php\/Expression_Language_Injection."},{"key":"e_1_3_2_1_48_1","unstructured":"Open Web Application Security Project. 2019. OWASP Benchmark Project. https:\/\/www.owasp.org\/index.php\/Benchmark."},{"key":"e_1_3_2_1_49_1","unstructured":"Open Web Application Security Project. 2019. Testing for SQL Wildcard Attacks (OWASP-DS-001). https:\/\/www.owasp.org\/index.php\/Testing_for_SQL_Wildcard_Attacks_(OWASP-DS-001)."},{"key":"e_1_3_2_1_50_1","unstructured":"Open Web Application Security Project. 2019. XSS Filter Evasion Cheat Sheet. https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet."},{"key":"e_1_3_2_1_51_1","unstructured":"OW2 Consortium. 2019. ASM. https:\/\/asm.ow2.io\/."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Sanjay Rawat Vivek Jain Ashish Kumar Lucian Cojocar Cristiano Giuffrida and Herbert Bos. 2017. VUzzer: Application-aware Evolutionary Fuzzing. In NDSS. https:\/\/www.vusec.net\/download\/?t=papers\/vuzzer_ndss17.pdf","DOI":"10.14722\/ndss.2017.23404"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3139337.3139341"},{"key":"e_1_3_2_1_55_1","unstructured":"Matthew Schwartz. 2019. Equifax's Data Breach Costs Hit $1.4 Billion. https:\/\/www.bankinfosecurity.com\/equifaxs-data-breach-costs-hit-14-billion-a-12473."},{"key":"e_1_3_2_1_56_1","unstructured":"Ashwin Seshagiri. 2015. How Hackers Made $1 Million by Stealing One News Release. https:\/\/www.nytimes.com\/2015\/08\/12\/business\/dealbook\/how-hackers-made-1-million-by-stealing-one-news-release.html?_r=0."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/AST.2019.00014"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516696"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3332371"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/2048066.2048145"},{"key":"e_1_3_2_1_61_1","unstructured":"Derek Staahl. 2016. Hack that targeted Arizona voter database was easy to prevent expert says. http:\/\/www.azfamily.com\/story\/32945105\/hack-that-targeted-arizona-voter-database-was-easy-to-prevent-expert-says."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1111037.1111070"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_3_2_1_64_1","volume-title":"Presented as part of the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12)","author":"Tang Yang","unstructured":"Yang Tang, Phillip Ames, Sravan Bhamidipati, Ashish Bijlani, Roxana Geambasu, and Nikhil Sarda. 2012. CleanOS: Limiting Mobile Data Exposure with Idle Eviction. In Presented as part of the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12). USENIX, Hollywood, CA, 77--91. https:\/\/www.usenix.org\/conference\/osdi12\/technical-sessions\/presentation\/tang"},{"key":"e_1_3_2_1_65_1","unstructured":"Terence Parr. 2019. ANTLR. https:\/\/www.antlr.org\/."},{"key":"e_1_3_2_1_66_1","unstructured":"The Apache Software Foundation. 2019. OGNL - Apache Commons OGNL - Developer Guide. https:\/\/commons.apache.org\/proper\/commons-ognl\/developer-guide.html."},{"key":"e_1_3_2_1_67_1","unstructured":"The Apache Software Foundation. 2019. Security. https:\/\/struts.apache.org\/security\/."},{"key":"e_1_3_2_1_68_1","unstructured":"The Eclipse Foundation. 2019. Jetty - Servlet Engine and Http Server. https:\/\/www.eclipse.org\/jetty\/."},{"key":"e_1_3_2_1_69_1","unstructured":"The MITRE Corporation. 2019. CWE-601: URL Redirection to Untrusted Site ('Open Redirect'). https:\/\/cwe.mitre.org\/data\/definitions\/601.html."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2593833.2593835"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542486"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2019599.2019600"},{"key":"e_1_3_2_1_73_1","unstructured":"World Wide Web Consortium. 2017. HTML 5.2. https:\/\/www.w3.org\/TR\/html52\/."},{"key":"e_1_3_2_1_74_1","unstructured":"World Wide Web Consortium. 2019. Parsing HTML Documents. https:\/\/html.spec.whatwg.org\/multipage\/parsing.html."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337293"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/2652483"}],"event":{"name":"ICSE '20: 42nd International Conference on Software Engineering","location":"Seoul South Korea","acronym":"ICSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","KIISE Korean Institute of Information Scientists and Engineers","IEEE CS"]},"container-title":["Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380326","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3377811.3380326","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:23:56Z","timestamp":1750202636000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380326"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,27]]},"references-count":76,"alternative-id":["10.1145\/3377811.3380326","10.1145\/3377811"],"URL":"https:\/\/doi.org\/10.1145\/3377811.3380326","relation":{},"subject":[],"published":{"date-parts":[[2020,6,27]]},"assertion":[{"value":"2020-10-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}