Later archive addition
Argus: All your (PHP) Injection-sinks are belong to us
Argues that injection-vulnerability detection built on hand-curated sink lists misses sinks the language interpreter itself provides, and derives the sink set automatically from PHP interpreter internals instead. Applied to three major PHP versions it identified 284 deserialization sinks and 22 XSS sinks, far beyond prior lists; feeding these to two static taint analyses and an exploit generator surfaced 13 previously unknown flaws in WordPress and its plugins, 11 assigned CVE IDs.
Record
- Researcher
- Rasoul Jahanshahi and Manuel Egele
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Rasoul Jahanshahi and Manuel Egele, first published at the original source. Preserved copies are kept so the citation survives its host.