{"id":"https://openalex.org/W2788782991","doi":"https://doi.org/10.1145/3178876.3186090","title":"Large-Scale Analysis of Style Injection by Relative Path Overwrite","display_name":"Large-Scale Analysis of Style Injection by Relative Path Overwrite","publication_year":2018,"publication_date":"2018-01-01","ids":{"openalex":"https://openalex.org/W2788782991","doi":"https://doi.org/10.1145/3178876.3186090","mag":"2788782991"},"language":"en","primary_location":{"id":"doi:10.1145/3178876.3186090","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3178876.3186090","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3186090&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 World Wide Web Conference on World Wide Web - WWW '18","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"http://dl.acm.org/ft_gateway.cfm?id=3186090&type=pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Sajjad Arshad","orcid":null},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Sajjad Arshad","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Seyed Ali Mirheidari","orcid":null},"institutions":[{"id":"https://openalex.org/I193223587","display_name":"University of Trento","ror":"https://ror.org/05trd4x28","country_code":"IT","type":"education","lineage":["https://openalex.org/I193223587"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Seyed Ali Mirheidari","raw_affiliation_strings":["University of Trento, Trento, Italy"],"affiliations":[{"raw_affiliation_string":"University of Trento, Trento, Italy","institution_ids":["https://openalex.org/I193223587"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Tobias Lauinger","orcid":null},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tobias Lauinger","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Bruno Crispo","orcid":null},"institutions":[{"id":"https://openalex.org/I193223587","display_name":"University of Trento","ror":"https://ror.org/05trd4x28","country_code":"IT","type":"education","lineage":["https://openalex.org/I193223587"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Bruno Crispo","raw_affiliation_strings":["University of Trento, Trento, Italy"],"affiliations":[{"raw_affiliation_string":"University of Trento, Trento, Italy","institution_ids":["https://openalex.org/I193223587"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Engin Kirda","orcid":null},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Engin Kirda","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"last","author":{"id":null,"display_name":"William Robertson","orcid":null},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"William Robertson","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I12912129"],"apc_list":null,"apc_paid":null,"fwci":1.2335,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.85003051,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"237","last_page":"246"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9922999739646912,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9918000102043152,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/markup-language","display_name":"Markup language","score":0.6651999950408936},{"id":"https://openalex.org/keywords/path","display_name":"Path (computing)","score":0.5946000218391418},{"id":"https://openalex.org/keywords/style","display_name":"Style (visual arts)","score":0.5579000115394592},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5015000104904175},{"id":"https://openalex.org/keywords/range","display_name":"Range (aeronautics)","score":0.4260999858379364},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.3546999990940094},{"id":"https://openalex.org/keywords/simple","display_name":"Simple (philosophy)","score":0.3522999882698059},{"id":"https://openalex.org/keywords/html","display_name":"HTML","score":0.34880000352859497}],"concepts":[{"id":"https://openalex.org/C45874996","wikidata":"https://www.wikidata.org/wiki/Q37045","display_name":"Markup language","level":3,"score":0.6651999950408936},{"id":"https://openalex.org/C2777735758","wikidata":"https://www.wikidata.org/wiki/Q817765","display_name":"Path (computing)","level":2,"score":0.5946000218391418},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5807999968528748},{"id":"https://openalex.org/C2776445246","wikidata":"https://www.wikidata.org/wiki/Q1792644","display_name":"Style (visual arts)","level":2,"score":0.5579000115394592},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5015000104904175},{"id":"https://openalex.org/C204323151","wikidata":"https://www.wikidata.org/wiki/Q905424","display_name":"Range (aeronautics)","level":2,"score":0.4260999858379364},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4169999957084656},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3546999990940094},{"id":"https://openalex.org/C2780586882","wikidata":"https://www.wikidata.org/wiki/Q7520643","display_name":"Simple (philosophy)","level":2,"score":0.3522999882698059},{"id":"https://openalex.org/C138708601","wikidata":"https://www.wikidata.org/wiki/Q8811","display_name":"HTML","level":3,"score":0.34880000352859497},{"id":"https://openalex.org/C89159866","wikidata":"https://www.wikidata.org/wiki/Q4119753","display_name":"Style sheet","level":3,"score":0.31929999589920044},{"id":"https://openalex.org/C186644900","wikidata":"https://www.wikidata.org/wiki/Q194152","display_name":"Parsing","level":2,"score":0.3160000145435333},{"id":"https://openalex.org/C93213560","wikidata":"https://www.wikidata.org/wiki/Q46441","display_name":"Cascading Style Sheets","level":3,"score":0.3082999885082245},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.30649998784065247},{"id":"https://openalex.org/C143050476","wikidata":"https://www.wikidata.org/wiki/Q194502","display_name":"Sink (geography)","level":2,"score":0.3025999963283539},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.29089999198913574},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.2892000079154968},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.28029999136924744},{"id":"https://openalex.org/C11392498","wikidata":"https://www.wikidata.org/wiki/Q11288","display_name":"Web server","level":3,"score":0.27619999647140503},{"id":"https://openalex.org/C113378726","wikidata":"https://www.wikidata.org/wiki/Q7310797","display_name":"Relative permeability","level":3,"score":0.27549999952316284},{"id":"https://openalex.org/C189139006","wikidata":"https://www.wikidata.org/wiki/Q166074","display_name":"XHTML","level":4,"score":0.2745000123977661},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.27320000529289246},{"id":"https://openalex.org/C21959979","wikidata":"https://www.wikidata.org/wiki/Q36774","display_name":"Web page","level":2,"score":0.2678000032901764}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3178876.3186090","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3178876.3186090","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3186090&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 World Wide Web Conference on World Wide Web - WWW '18","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1811.00917","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1811.00917","pdf_url":"https://arxiv.org/pdf/1811.00917","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:iris.unitn.it:11572/228523.5","is_oa":false,"landing_page_url":"http://hdl.handle.net/11572/228523","pdf_url":null,"source":{"id":"https://openalex.org/S4306401913","display_name":"Institutional Research Information System (Universit\u00e0 degli Studi di Trento)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I193223587","host_organization_name":"University of Trento","host_organization_lineage":["https://openalex.org/I193223587"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"04 Convegni (Proceedings)::04.1 Saggio in atti di convegno (Paper in proceedings)"}],"best_oa_location":{"id":"doi:10.1145/3178876.3186090","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3178876.3186090","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3186090&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 World Wide Web Conference on World Wide Web - WWW '18","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4228632944","display_name":"SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality","funder_award_id":"1703454","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2788782991.pdf","grobid_xml":"https://content.openalex.org/works/W2788782991.grobid-xml"},"referenced_works_count":17,"referenced_works":["https://openalex.org/W1974977720","https://openalex.org/W1990421186","https://openalex.org/W1991074244","https://openalex.org/W2011875300","https://openalex.org/W2049214202","https://openalex.org/W2049869570","https://openalex.org/W2057718232","https://openalex.org/W2074261689","https://openalex.org/W2077204203","https://openalex.org/W2094415856","https://openalex.org/W2103262407","https://openalex.org/W2110986027","https://openalex.org/W2169868363","https://openalex.org/W2170920217","https://openalex.org/W2510134782","https://openalex.org/W2743909715","https://openalex.org/W2765755114"],"related_works":[],"abstract_inverted_index":{"Relative":[0],"Path":[1],"Overwrite":[2],"(RPO)":[3],"is":[4,23],"a":[5,42,48,50,87,99,200],"recent":[6],"technique":[7],"to":[8,40,68,118,165,175,182,189,211],"inject":[9,69],"style":[10,17,70,81,125,184],"directives":[11,71],"into":[12],"sites":[13,137],"even":[14],"when":[15],"no":[16],"sink":[18],"or":[19],"markup":[20],"injection":[21,53,82,126],"vulnerability":[22,54],"present.":[24],"It":[25],"exploits":[26],"differences":[27],"in":[28,59,64,138,161],"how":[29],"browsers":[30],"and":[31,122,168],"web":[32],"servers":[33],"interpret":[34],"relative":[35],"paths":[36],"(i.e.,":[37],"path":[38],"confusion)":[39],"make":[41,169],"HTML":[43],"page":[44],"reference":[45],"itself":[46],"as":[47,197],"stylesheet;":[49],"simple":[51,179],"text":[52],"along":[55],"with":[56],"browsers\u00bb":[57],"leniency":[58],"parsing":[60],"CSS":[61],"resources":[62],"results":[63],"an":[65],"attacker\u00bbs":[66],"ability":[67],"that":[72,96,132,208],"will":[73],"be":[74,157,190,212],"interpreted":[75],"by":[76,199],"the":[77,111,116,120,136,139],"browser.":[78],"Even":[79],"though":[80],"may":[83],"appear":[84],"less":[85],"serious":[86],"threat":[88],"than":[89,153],"script":[90,176],"injection,":[91,177],"it":[92,97],"has":[93],"been":[94],"shown":[95],"enables":[98],"range":[100,201],"of":[101,115,124,135,150,193,202],"attacks,":[102],"including":[103],"secret":[104],"exfiltration.":[105],"In":[106,173],"this":[107,194],"paper,":[108],"we":[109,209],"present":[110],"first":[112],"large-scale":[113],"study":[114],"Web":[117],"measure":[119],"prevalence":[121],"significance":[123],"using":[127],"RPO.":[128],"Our":[129],"work":[130],"shows":[131],"around":[133],"9%":[134],"Alexa":[140],"Top":[141],"10,000":[142],"contain":[143],"at":[144],"least":[145],"one":[146,154],"vulnerable":[147],"page,":[148],"out":[149],"which":[151],"more":[152],"third":[155],"can":[156],"exploited.":[158],"We":[159],"analyze":[160],"detail":[162],"various":[163],"impediments":[164],"successful":[166],"exploitation,":[167],"recommendations":[170],"for":[171],"remediation.":[172],"contrast":[174],"relatively":[178],"countermeasures":[180],"exist":[181],"mitigate":[183],"injection.":[185],"However,":[186],"there":[187],"appears":[188],"little":[191],"awareness":[192],"attack":[195],"vector":[196],"evidenced":[198],"popular":[203],"Content":[204],"Management":[205],"Systems":[206],"(CMSes)":[207],"found":[210],"exploitable.":[213]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2018-03-06T00:00:00"}
