• Home
  • Search
  • The essence of command injection attacks in web applications
  • Cite Icon137
  • https://doi.org/10.1145/1111320.1111070Copy DOI Icon

The essence of command injection attacks in web applications

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Web applications typically interact with a back-end database to retrieve persistent data and then present the data to the user as dynamically generated output, such as HTML web pages. However, this interaction is commonly done through a low-level API by dynamically constructing query strings within a general-purpose programming language, such as Java. This low-level interaction is ad hoc because it does not take into account the structure of the output language. Accordingly, user inputs are treated as isolated lexical entities which, if not properly sanitized, can cause the web application to generate unintended output. This is called a command injection attack , which poses a serious threat to web application security. This paper presents the first formal definition of command injection attacks in the context of web applications, and gives a sound and complete algorithm for preventing them based on context-free grammars and compiler parsing techniques. Our key observation is that, for an attack to succeed, the input that gets propagated into the database query or the output document must change the intended syntactic structure of the query or document. Our definition and algorithm are general and apply to many forms of command injection attacks. We validate our approach with SqlCheckS , an implementation for the setting of SQL command injection attacks. We evaluated SqlCheckS on real-world web applications with systematically compiled real-world attack data as input. SqlCheckS produced no false positives or false negatives, incurred low runtime overhead, and applied straightforwardly to web applications written in different languages.

Similar Papers
  • Conference Article
  • Citations555

The essence of command injection attacks in web applications

  • Jan 11, 2006
  • Zhendong Su +1
  • Conference Article
  • Citations3

Attacks on Vulnerable Web Applications

  • Jun 25, 2021
  • Nikhil Kumar Singh +3
  • Research Article
  • Citations9

A Prevention Model for Session Hijack Attacks in Wireless Networks Using Strong and Encrypted Session ID

  • Sep 01, 2014
  • Cybernetics and Information Technologies
  • S S Manivannan +1
  • Book Chapter
  • Citations4

Toward Exposing Timing-Based Probing Attacks in Web Applications

  • Jan 01, 2016
  • Jian Mao +4
  • Book Chapter
  • Citations4

An Interpretive Saga of SQL Injection Attacks

  • Sep 29, 2022
  • Saloni Manhas
  • Conference Article
  • Citations7

Cross Channel Scripting (XCS) Attacks in Web Applications: Detection and Mitigation Approaches

  • Oct 01, 2018
  • R Madhusudhan +1
  • Book Chapter
  • Citations7

Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application

  • Jan 01, 2015
  • Nor Fatimah Awang +1
  • Conference Article
  • Citations10

Causes and Prevention of SQL Injection Attacks in Web Applications

  • Dec 28, 2016
  • Stephanos Mavromoustakos +4
  • Research Article
  • Citations31

A Survey on Web Application Security

  • Oct 05, 2020
  • International Journal of Scientific Research in Computer Science, Engineering and Information Technology
  • Danish Mairaj Inamdar +1
  • Book Chapter

Predictive Analytics of Injection Attacks in Web Applications

  • Aug 31, 2025
  • U Farjana +1
  • Research Article
  • Citations76

Sound and precise analysis of web applications for injection vulnerabilities

  • Jun 10, 2007
  • ACM SIGPLAN Notices
  • Gary Wassermann +1
  • Research Article
  • Citations13

A Method of Detecting Sql Injection Attack to Secure Web Applications

  • Nov 30, 2012
  • International Journal of Distributed and Parallel systems
  • Sruthy Manmadhan
  • Research Article
  • Citations12

Token based Detection and Neural Network based Reconstruction framework against code injection vulnerabilities

  • Jun 22, 2018
  • Journal of Information Security and Applications
  • Teresa K George +2
  • Conference Article
  • Citations61

Intrusion recovery for database-backed web applications

  • Oct 23, 2011
  • Ramesh Chandra +4
  • Book Chapter
  • Citations3

Identifying and Mitigating Against XSS Attacks in Web Applications

  • May 15, 2021
  • R Shashidhara +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.