{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:54:53Z","timestamp":1783007693748,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":66,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1145\/3634737.3661137","type":"proceedings-article","created":{"date-parts":[[2024,6,28]],"date-time":"2024-06-28T11:51:38Z","timestamp":1719575498000},"page":"1523-1538","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["What All the PHUZZ Is About: A Coverage-guided Fuzzer for Finding Vulnerabilities in PHP Web Applications"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3055-0823","authenticated-orcid":false,"given":"Sebastian","family":"Neef","sequence":"first","affiliation":[{"name":"Security in Telecommunications, Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-7341-1366","authenticated-orcid":false,"given":"Lorenz","family":"Kleissner","sequence":"additional","affiliation":[{"name":"Security in Telecommunications, Technische Universit\u00e4t Berlin, Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5372-4825","authenticated-orcid":false,"given":"Jean-Pierre","family":"Seifert","sequence":"additional","affiliation":[{"name":"Security in Telecommunications, Technische Universit\u00e4t Berlin, Berlin, Germany"},{"name":"Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978380"},{"key":"e_1_3_2_1_2_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Alhuzali Abeer","year":"2018","unstructured":"Abeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, and VN Venkatakrishnan. 2018. NAVEX: Precise and scalable exploit generation for dynamic web applications. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, USA, 377--392."},{"key":"e_1_3_2_1_3_1","unstructured":"Ionut Arghire. 2023. 1 Million WordPress Sites Impacted by Exploited Plugin Vulnerability - SecurityWeek. https:\/\/www.securityweek.com\/1-million-wordpress-sites-impacted-by-exploited-plugin-vulnerability\/"},{"key":"e_1_3_2_1_4_1","unstructured":"Ionut Arghire. 2023. Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability - SecurityWeek. https:\/\/www.securityweek.com\/millions-of-wordpress-sites-patched-against-critical-jetpack-vulnerability\/"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00083"},{"key":"e_1_3_2_1_6_1","unstructured":"Automattic Inc. 2022. Submission Terms | WPScan. https:\/\/wpscan.com\/submission-terms\/"},{"key":"e_1_3_2_1_7_1","unstructured":"Automattic Inc. 2023. WooCommerce - Open Source Ecommerce Platform. https:\/\/woocommerce.com\/"},{"key":"e_1_3_2_1_8_1","unstructured":"The MITRE Corporation. 2008. CWE - CWE-699: Software Development (4.9). https:\/\/cwe.mitre.org\/data\/definitions\/699.html"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23262"},{"key":"e_1_3_2_1_10_1","volume-title":"Docker: Accelerated, Containerized Application Development. https:\/\/docker.com\/","author":"Docker Inc.","year":"2023","unstructured":"Docker Inc. 2023. Docker: Accelerated, Containerized Application Development. https:\/\/docker.com\/"},{"key":"e_1_3_2_1_11_1","unstructured":"Docker Inc. 2023. Docker Compose overview | Docker Documentation. https:\/\/docs.docker.com\/compose\/"},{"key":"e_1_3_2_1_12_1","volume-title":"DIMVA 2010, Bonn, Germany, July 8--9, 2010. Proceedings 7. Springer, Springer Berlin Heidelberg","author":"Doup\u00e9 Adam","year":"2010","unstructured":"Adam Doup\u00e9, Marco Cova, and Giovanni Vigna. 2010. Why Johnny can't pentest: An analysis of black-box web vulnerability scanners. In Detection of Intrusions and Malware, and Vulnerability Assessment: 7th International Conference, DIMVA 2010, Bonn, Germany, July 8--9, 2010. Proceedings 7. Springer, Springer Berlin Heidelberg, Berlin, Heidelberg, 111--131."},{"key":"e_1_3_2_1_13_1","unstructured":"DVWAteam. 2023. GitHub-digininja\/DVWA: Damn Vulnerable Web Application (DVWA). https:\/\/github.com\/digininja\/DVWA"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 14th USENIX Conference on Offensive Technologies. USENIX Association, USA, 10--10","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL++ combining incremental steps of fuzzing research. In Proceedings of the 14th USENIX Conference on Offensive Technologies. USENIX Association, USA, 10--10."},{"key":"e_1_3_2_1_15_1","unstructured":"FrancescoArcuri13. 2023. Info of the code \u00b7 Issue #14 \u00b7 sefcom\/Witcher. https:\/\/github.com\/sefcom\/Witcher\/issues\/14"},{"key":"e_1_3_2_1_16_1","unstructured":"FrancescoArcuri13. 2023. run-single-experiment.sh \u00b7 Issue #1 \u00b7 sefcom\/Witcher-experiment. https:\/\/github.com\/sefcom\/Witcher-experiment\/issues\/1"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/icse.2009.5070546"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2022.29"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1292414.1292416"},{"key":"e_1_3_2_1_20_1","volume-title":"NDSS","volume":"8","author":"Godefroid Patrice","year":"2008","unstructured":"Patrice Godefroid, Michael Y Levin, David A Molnar, et al. 2008. Automated whitebox fuzz testing.. In NDSS, Vol. 8. The Internet Society, USA, 151--166."},{"key":"e_1_3_2_1_21_1","unstructured":"Google LLC. 2023. GitHub - google\/fuzztest. https:\/\/github.com\/google\/fuzztest"},{"key":"e_1_3_2_1_22_1","unstructured":"Google LLC. 2023. GitHub - google\/honggfuzz: Security oriented software fuzzer. Supports evolutionary feedback-driven fuzzing based on code coverage (SW and HW based). https:\/\/github.com\/google\/honggfuzz"},{"key":"e_1_3_2_1_23_1","unstructured":"Google LLC. 2023. OSS-Fuzz | Documentation for OSS-Fuzz. https:\/\/google.github.io\/oss-fuzz\/"},{"key":"e_1_3_2_1_24_1","unstructured":"Bernardo Damele Assumpcao Guimaraes and Miroslav Stampar. 2006. sqlmap: automatic SQL injection and database takeover tool. https:\/\/sqlmap.org\/"},{"key":"e_1_3_2_1_25_1","volume-title":"Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities.","author":"G\u00fcler Emre","year":"2024","unstructured":"Emre G\u00fcler, Sergej Schumilo, Moritz Schloegel, Nils Bars, Philipp G\u00f6rz, Xinyi Xu, Cemal Kaygusuz, and Thorsten Holz. 2024. Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471859"},{"key":"e_1_3_2_1_27_1","unstructured":"Invicti Security Corp. 2023. Acunetix | Web Application Security Scanner. https:\/\/www.acunetix.com\/"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2006.29"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23126"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0002-y"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2019.2946563"},{"key":"e_1_3_2_1_32_1","volume-title":"Wfuzz: The Web fuzzer --- Wfuzz 2.1.4 documentation. https:\/\/wfuzz.readthedocs.io\/","author":"Mendez Xavi","year":"2011","unstructured":"Xavi Mendez. 2011. Wfuzz: The Web fuzzer --- Wfuzz 2.1.4 documentation. https:\/\/wfuzz.readthedocs.io\/"},{"key":"e_1_3_2_1_33_1","unstructured":"Malik Messellem. 2014. bWAPP a buggy web app. http:\/\/www.itsecgames.com\/"},{"key":"e_1_3_2_1_34_1","unstructured":"Microsoft. 2024. Fast and reliable end-to-end testing for modern web apps | Playwright. https:\/\/playwright.dev\/"},{"key":"e_1_3_2_1_35_1","unstructured":"Larissa Moroz. 2018. bWAPP latest modified for PHP7. https:\/\/github.com\/lmoroz\/bWAPP"},{"key":"e_1_3_2_1_36_1","volume-title":"PHUZZ: A grey-box fuzzer for PHP web applications. https:\/\/github.com\/gehaxelt\/phuzz","author":"Neef Sebastian","year":"2024","unstructured":"Sebastian Neef and Lorenz Kleissner. 2024. PHUZZ: A grey-box fuzzer for PHP web applications. https:\/\/github.com\/gehaxelt\/phuzz"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC2616"},{"key":"e_1_3_2_1_38_1","unstructured":"OWASP Foundation. 2021. OWASP Top 10:2021. https:\/\/owasp.org\/Top10\/"},{"key":"e_1_3_2_1_39_1","unstructured":"OWASP Foundation. 2023. Command Injection | OWASP Foundation. https:\/\/owasp.org\/www-community\/attacks\/Command_Injection"},{"key":"e_1_3_2_1_40_1","unstructured":"OWASP Foundation. 2023. Cross Site Scripting (XSS) | OWASP Foundation. https:\/\/owasp.org\/www-community\/attacks\/xss\/"},{"key":"e_1_3_2_1_41_1","unstructured":"OWASP Foundation. 2023. Deserialization of untrusted data | OWASP Foundation. https:\/\/owasp.org\/www-community\/vulnerabilities\/Deserialization_of_untrusted_data"},{"key":"e_1_3_2_1_42_1","unstructured":"OWASP Foundation. 2023. Path Traversal | OWASP Foundation. https:\/\/owasp.org\/www-community\/attacks\/Path_Traversal"},{"key":"e_1_3_2_1_43_1","unstructured":"OWASP Foundation. 2023. SQL Injection | OWASP Foundation. https:\/\/owasp.org\/www-community\/attacks\/SQL_Injection"},{"key":"e_1_3_2_1_44_1","unstructured":"OWASP Foundation. 2023. Unvalidated Redirects and Forwards - OWASP Cheat Sheet Series. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html"},{"key":"e_1_3_2_1_45_1","unstructured":"OWASP Foundation. 2023. XML External Entity (XXE) Processing| OWASP Foundation. https:\/\/owasp.org\/www-community\/vulnerabilities\/XML_External_Entity_(XXE)_Processing"},{"key":"e_1_3_2_1_46_1","unstructured":"PortSwigger. 2023. Burp Suite Professional - PortSwigger. https:\/\/portswigger.net\/burp\/pro"},{"key":"e_1_3_2_1_47_1","volume-title":"June","year":"2023","unstructured":"Q-Success. 2023. Usage Statistics and Market Share of PHP for Websites, June 2023. https:\/\/w3techs.com\/technologies\/details\/pl-php"},{"key":"e_1_3_2_1_48_1","volume-title":"June","year":"2023","unstructured":"Q-Success. 2023. Usage Statistics and Market Share of Server-side Programming Languages for Websites, June 2023. https:\/\/w3techs.com\/technologies\/overview\/programming_language"},{"key":"e_1_3_2_1_49_1","volume-title":"Requests: HTTP for Humans --- Requests documentation. https:\/\/requests.readthedocs.io\/en\/latest\/","author":"Reitz Kenneth","year":"2023","unstructured":"Kenneth Reitz. 2023. Requests: HTTP for Humans --- Requests documentation. https:\/\/requests.readthedocs.io\/en\/latest\/"},{"key":"e_1_3_2_1_50_1","volume-title":"Xdebug: Documentation Code Coverage Analysis. https:\/\/xdebug.org\/docs\/code_coverage","author":"Rethans Derick","year":"2002","unstructured":"Derick Rethans. 2002. Xdebug: Documentation Code Coverage Analysis. https:\/\/xdebug.org\/docs\/code_coverage"},{"key":"e_1_3_2_1_51_1","unstructured":"Andres Riancho. 2014. w3af - Open Source Web Application Security Scanner. https:\/\/w3af.org\/"},{"key":"e_1_3_2_1_52_1","unstructured":"Thomas Sanoop. 2015. XVWA is a badly coded web application written in PHP\/MySQL that helps security enthusiasts to learn application security. https:\/\/github.com\/s4n7h0\/xvwa"},{"key":"e_1_3_2_1_53_1","unstructured":"Nicolas Surribas. 2006. Wapiti: a Free and Open-Source web-application vulnerability scanner in Python. https:\/\/wapiti-scanner.github.io\/"},{"key":"e_1_3_2_1_54_1","volume-title":"PHP: Description of core php.ini directives - Manual. https:\/\/www.php.net\/manual\/en\/ini.core.php","author":"The PHP Group","year":"2023","unstructured":"The PHP Group. 2023. PHP: Description of core php.ini directives - Manual. https:\/\/www.php.net\/manual\/en\/ini.core.php"},{"key":"e_1_3_2_1_55_1","volume-title":"PHP: Errors - Manual. https:\/\/www.php.net\/manual\/en\/language.errors.php","author":"The PHP Group","year":"2023","unstructured":"The PHP Group. 2023. PHP: Errors - Manual. https:\/\/www.php.net\/manual\/en\/language.errors.php"},{"key":"e_1_3_2_1_56_1","volume-title":"PHP: History of PHP - Manual. https:\/\/www.php.net\/manual\/en\/history.php.php","author":"The PHP Group","year":"2023","unstructured":"The PHP Group. 2023. PHP: History of PHP - Manual. https:\/\/www.php.net\/manual\/en\/history.php.php"},{"key":"e_1_3_2_1_57_1","unstructured":"The PHP Group. 2023. PHP: register_shutdown_function - Manual. https:\/\/www.php.net\/manual\/en\/function.register-shutdown-function.php"},{"key":"e_1_3_2_1_58_1","unstructured":"The PHP Group. 2023. PHP: uopz - Manual. https:\/\/www.php.net\/manual\/en\/book.uopz.php"},{"key":"e_1_3_2_1_59_1","volume-title":"2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, IEEE","author":"Trickel Erik","year":"2022","unstructured":"Erik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel, Giovanni Vigna, Christopher Kruegel, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, and Adam Doup\u00e9. 2022. Toss a fault to your witcher: Applying grey-box coverage-guided mutational fuzzing to detect sql and command injection vulnerabilities. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, IEEE, San Francisco, CA, USA, 116--133."},{"key":"e_1_3_2_1_60_1","volume-title":"2023 IEEE Security and Privacy Workshops (SPW). IEEE, IEEE","author":"Ulitzsch Vincent","year":"2023","unstructured":"Vincent Ulitzsch, Deniz Scholz, and Dominik Maier. 2023. ASanity: On Bug Shadowing by Early ASan Exits. In 2023 IEEE Security and Privacy Workshops (SPW). IEEE, IEEE, San Francisco, California, USA, 364--370."},{"key":"e_1_3_2_1_61_1","volume-title":"Proceedings, Part I 26","author":"van Rooij Orpheas","year":"2021","unstructured":"Orpheas van Rooij, Marcos Antonios Charalambous, Demetris Kaizer, Michalis Papaevripides, and Elias Athanasopoulos. 2021. webfuzz: Grey-box fuzzing for web applications. In Computer Security-ESORICS 2021: 26th European Symposium on Research in Computer Security, Darmstadt, Germany, October 4--8, 2021, Proceedings, Part I 26. Springer, Springer Cham, Darmstadt, Germany, 152--172."},{"key":"e_1_3_2_1_62_1","unstructured":"Joe Watkins. 2023. PCOV - CodeCoverage compatible driver for PHP. https:\/\/github.com\/krakjoe\/pcov\/"},{"key":"e_1_3_2_1_63_1","unstructured":"Michal Zalewski. 2014. american fuzzy lop. https:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"e_1_3_2_1_64_1","unstructured":"ZAP Dev Team. 2023. OWASP ZAP. https:\/\/www.zaproxy.org\/"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.3390\/electronics11050758"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3512345"}],"event":{"name":"ASIA CCS '24: 19th ACM Asia Conference on Computer and Communications Security","location":"Singapore Singapore","acronym":"ASIA CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 19th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661137","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:44:07Z","timestamp":1750290247000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661137"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":66,"alternative-id":["10.1145\/3634737.3661137","10.1145\/3634737"],"URL":"https:\/\/doi.org\/10.1145\/3634737.3661137","relation":{},"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"2024-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}