Splendor: Static Detection of Stored XSS in Modern Web Applications
He Su, Feng Li, Lili Xu, Wenbo Hu, Yujie Sun, Qing Sun, Huina Chao, Wei Huo
Abstract
In modern websites, stored Cross-Site Scripting (XSS) is the most dangerous XSS vulnerability, which can store payloads in the web system and be triggered directly by the victim. Database (DB) as the most commonly used storage medium for data on websites is therefore also the most common place where stored XSS occurs. Due to the modularity of modern programming architectures, the complex underlying database operations will often be encapsulated and abstracted as a Data Access Layer (DAL) to provide unified data access services to the business layer. The heavy use of Object-Oriented (OO) and dynamic language features involved in the encapsulation makes it increasingly challenging for static taint analysis tools to understand how tainted data flows between the source code and the exact locations in database.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4d7a20cc-40bd-4f52-94c4-2e3f6aa4abe2Cited by top-tier papers7
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Pointer Analysis for Database-Backed ApplicationsYufei Liang, Teng Zhang, Ganlin Li, Tian Tan et al.PLDI 2025 · 5 citations
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao et al.FSE 2024 · 5 citations
- Detecting Broken Object-Level Authorization Vulnerabilities in Database-Backed ApplicationsYongheng Huang, Chenghang Shi, Jie Lu, Haofeng Li et al.CCS 2024 · 4 citations
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun et al.NDSS 2024
Related papers
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script GadgetsSebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava et al.CCS 2017 · 62 citations
- Spider-Scents: Grey-box Database-aware Web Scanning for Stored XSSEric Olsson, Benjamin Eriksson, Adam Doupé, Andrei SabelfeldUSENIX Security 2024 · 8 citations
