Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines
Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including cross-site scripting, have caused damages for both web site owners and users. Cross-site scripting vulnerabilities are easy to exploit but difficu...
| Main Authors: | , , , |
|---|---|
| Format: | Article |
| Language: | English |
| Published: |
Indian Society for Education and Environment
2015
|
| Online Access: | http://psasir.upm.edu.my/id/eprint/55151/ http://psasir.upm.edu.my/id/eprint/55151/1/Removing%20cross-site%20scripting%20vulnerabilities%20from%20web%20applications%20using%20the%20OWASP%20ESAPI%20security%20guidelines.pdf |
| _version_ | 1848852726529654784 |
|---|---|
| author | Hydara, Isatou Md Sultan, Abu Bakar Zulzalil, Hazura Admodisastro, Novia Indriaty |
| author_facet | Hydara, Isatou Md Sultan, Abu Bakar Zulzalil, Hazura Admodisastro, Novia Indriaty |
| author_sort | Hydara, Isatou |
| building | UPM Institutional Repository |
| collection | Online Access |
| description | Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including cross-site scripting, have caused damages for both web site owners and users. Cross-site scripting vulnerabilities are easy to exploit but difficult to eliminate. Most solutions provided only focus on preventing attacks or detecting the vulnerabilities. Very few research works have addressed eliminating these vulnerabilities from the web applications source codes. In this paper, we propose an approach to remove cross-site scripting vulnerabilities from the source code before an application is deployed. We make use of the OWASP cross-site scripting prevention rules as guideline in our approach. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluation results have indicated promising results. |
| first_indexed | 2025-11-15T10:42:40Z |
| format | Article |
| id | upm-55151 |
| institution | Universiti Putra Malaysia |
| institution_category | Local University |
| language | English |
| last_indexed | 2025-11-15T10:42:40Z |
| publishDate | 2015 |
| publisher | Indian Society for Education and Environment |
| recordtype | eprints |
| repository_type | Digital Repository |
| spelling | upm-551512019-11-29T02:57:17Z http://psasir.upm.edu.my/id/eprint/55151/ Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines Hydara, Isatou Md Sultan, Abu Bakar Zulzalil, Hazura Admodisastro, Novia Indriaty Software security vulnerabilities are present in many web applications and have led to many successful attacks on a daily basis. These attacks, including cross-site scripting, have caused damages for both web site owners and users. Cross-site scripting vulnerabilities are easy to exploit but difficult to eliminate. Most solutions provided only focus on preventing attacks or detecting the vulnerabilities. Very few research works have addressed eliminating these vulnerabilities from the web applications source codes. In this paper, we propose an approach to remove cross-site scripting vulnerabilities from the source code before an application is deployed. We make use of the OWASP cross-site scripting prevention rules as guideline in our approach. The proposed approach is, so far, only implemented and validated on Java-based Web applications, although it can be implemented in other programming languages with slight modifications. Initial evaluation results have indicated promising results. Indian Society for Education and Environment 2015 Article PeerReviewed text en http://psasir.upm.edu.my/id/eprint/55151/1/Removing%20cross-site%20scripting%20vulnerabilities%20from%20web%20applications%20using%20the%20OWASP%20ESAPI%20security%20guidelines.pdf Hydara, Isatou and Md Sultan, Abu Bakar and Zulzalil, Hazura and Admodisastro, Novia Indriaty (2015) Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines. Indian Journal of Science and Technology, 8 (30). pp. 1-5. ISSN 0974-6846; ESSN: 0974-5645 http://www.indjst.org/index.php/indjst/article/view/87182/0 10.17485/ijst/2015/v8i30/87182 |
| spellingShingle | Hydara, Isatou Md Sultan, Abu Bakar Zulzalil, Hazura Admodisastro, Novia Indriaty Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title | Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title_full | Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title_fullStr | Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title_full_unstemmed | Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title_short | Removing cross-site scripting vulnerabilities from web applications using the OWASP ESAPI security guidelines |
| title_sort | removing cross-site scripting vulnerabilities from web applications using the owasp esapi security guidelines |
| url | http://psasir.upm.edu.my/id/eprint/55151/ http://psasir.upm.edu.my/id/eprint/55151/ http://psasir.upm.edu.my/id/eprint/55151/ http://psasir.upm.edu.my/id/eprint/55151/1/Removing%20cross-site%20scripting%20vulnerabilities%20from%20web%20applications%20using%20the%20OWASP%20ESAPI%20security%20guidelines.pdf |