2012 · 117 citations · 12 references
Sql InjectionVulnerability Assessment (Computing)Software SecurityEngineeringProgram AnalysisInformation SecurityWeb SecurityWeb Application VulnerabilitiesSecurity TestingDatabase SecuritySecurity EngineQuery LanguageWeb SupportLanguage-based SecurityCompany StatisticsData Security
Web applications rely on databases for critical data, making them frequent targets of SQL injection and XSS attacks, which are among the most common application‑layer exploits and top OWASP vulnerabilities. The paper reviews types of SQL injection and XSS attacks, their vulnerabilities, and prevention techniques, and proposes future countermeasure developments. The authors conduct a detailed survey of SQL injection and XSS attack types, vulnerabilities, and mitigation strategies. The survey identifies current vulnerabilities and outlines future expectations for countermeasures against SQL injection.
Today almost all organizations have improved their performance through allowing more information exchange within their organization as well as between their distributers, suppliers, and customers using web support. Databases are central to the modern websites as they provide necessary data as well as stores critical information such as user credentials, financial and payment information, company statistics etc. These websites have been continuously targeted by highly motivated malicious users to acquire monetary gain. Structured Query Language (SQL) injection and Cross Site Scripting Attack (XSS) is perhaps one of the most common application layer attack technique used by attacker to deface the website, manipulate or delete the content through inputting unwanted command strings. Structured Query Language Injection Attacks (SQLIA) is ranked 1st in the Open Web Application Security Project (OWASP) [1] top 10 vulnerability list and has resulted in massive attacks on a number of websites in the past few years. In this paper, we present a detailed review on various types of Structured Query Language Injection attacks, Cross Site Scripting Attack, vulnerabilities, and prevention techniques. Besides presenting our findings from the survey, we also propose future expectations and possible development of countermeasures against Structured Query Language Injection attacks.
12
Automatic creation of SQL Injection and cross-site scripting attacks
Adam Kieyzun, Philip J. Guo, Karthick Jayaraman et al. · 2009 · 340 citations · Full text
Prithvi Bisht, P. Madhusudan, V. N. Venkatakrishnan · ACM Transactions on Information and System Security · 2010 · 167 citations
Combinatorial Approach for Preventing SQL Injection Attacks
R. Ezumalai, G. Aghila · 2009 · 46 citations