English

Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection (Extended Version)

Cryptography and Security 2016-08-11 v2

Abstract

We present a formal approach that exploits attacks related to SQL Injection (SQLi) searching for security flaws in a web application. We give a formal representation of web applications and databases, and show that our formalization effectively exploits SQLi attacks. We implemented our approach in a prototype tool called SQLfast and we show its efficiency on real-world case studies, including the discovery of an attack on Joomla! that no other tool can find.

Cite

@article{arxiv.1605.00358,
  title  = {Formal Analysis of Vulnerabilities of Web Applications Based on SQL Injection (Extended Version)},
  author = {Federico De Meo and Marco Rocchetto and Luca Viganò},
  journal= {arXiv preprint arXiv:1605.00358},
  year   = {2016}
}
R2 v1 2026-06-22T13:46:08.411Z