Automatic Creation of SQL Injection and Cross-Site Scripting Attacks
Source: Stanford University
The authors present a technique for finding security vulnerabilities in Web applications. SQL Injection (SQLI) and cross-site scripting (XSS) attacks are widespread forms of attack in which the attacker crafts the input to the application to access or modify user data and execute malicious code. In the most serious attacks (called second-order, or persistent, XSS), an attacker can corrupt a database so as to cause subsequent users to execute malicious code. This paper presents an automatic technique for creating inputs that expose SQLI and XSS vulnerabilities.
| Format: | Size: | 322.80 | |
| Date: | Sep 2008 |



