A Practical Experience on the Impact of Plugins in Web Security
Title | A Practical Experience on the Impact of Plugins in Web Security |
Publication Type | Conference Paper |
Year of Publication | 2014 |
Authors | Coelho Martins da Fonseca, J.C., Amorim Vieira, M.P. |
Conference Name | Reliable Distributed Systems (SRDS), 2014 IEEE 33rd International Symposium on |
Date Published | Oct |
Keywords | content management, content management system, Cross Site Scripting, Databases, false positive rates, Internet, Manuals, plugins, program diagnostics, security, security of data, SQL injection vulnerabilities, static analysis, static code analysis tools, Testing, vulnerabilities, Web application plugin vulnerabilities, Web applications, Web pages, web security |
Abstract | In an attempt to support customization, many web applications allow the integration of third-party server-side plugins that offer diverse functionality, but also open an additional door for security vulnerabilities. In this paper we study the use of static code analysis tools to detect vulnerabilities in the plugins of the web application. The goal is twofold: 1) to study the effectiveness of static analysis on the detection of web application plugin vulnerabilities, and 2) to understand the potential impact of those plugins in the security of the core web application. We use two static code analyzers to evaluate a large number of plugins for a widely used Content Manage-ment System. Results show that many plugins that are current-ly deployed worldwide have dangerous Cross Site Scripting and SQL Injection vulnerabilities that can be easily exploited, and that even widely used static analysis tools may present disappointing vulnerability coverage and false positive rates. |
URL | https://ieeexplore.ieee.org/document/6983376 |
DOI | 10.1109/SRDS.2014.20 |
Citation Key | 6983376 |
- security of data
- web security
- Web pages
- web applications
- Web application plugin vulnerabilities
- vulnerabilities
- testing
- static code analysis tools
- static analysis
- SQL injection vulnerabilities
- content management
- security
- program diagnostics
- plugins
- Manuals
- internet
- false positive rates
- Databases
- Cross Site Scripting
- content management system