BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
Fuente:
arXiv
Saved in:
| Main Authors: | Dharmaadi, I Putu Arya, Alhanahnah, Mohannad, Pham, Van-Thuan, Mohsen, Fadi, Turkmen, Fatih |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Fuzzing Frameworks for Server-side Web Applications: A Survey
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)
by: Corradini, Davide, et al.
Published: (2025)
Exposing and Defending Membership Leakage in Vulnerability Prediction Models
by: Liao, Yihan, et al.
Published: (2025)
by: Liao, Yihan, et al.
Published: (2025)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025)
by: Yang, Yanjing, et al.
Published: (2025)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
by: Yang, Guan-Yan, et al.
Published: (2025)
by: Yang, Guan-Yan, et al.
Published: (2025)
Testing Access-Control Configuration Changes for Web Applications
by: Xiang, Chengcheng, et al.
Published: (2025)
by: Xiang, Chengcheng, et al.
Published: (2025)
Following Dragons: Code Review-Guided Fuzzing
by: Luu, Viet Hoang, et al.
Published: (2026)
by: Luu, Viet Hoang, et al.
Published: (2026)
Taint Analysis for Graph APIs Focusing on Broken Access Control
by: Lambers, Leen, et al.
Published: (2025)
by: Lambers, Leen, et al.
Published: (2025)
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
by: Gao, Zeyu, et al.
Published: (2025)
by: Gao, Zeyu, et al.
Published: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code
by: Blain, Dominik, et al.
Published: (2026)
by: Blain, Dominik, et al.
Published: (2026)
Cross-Ecosystem Vulnerability Analysis for Python Applications
by: Alexopoulos, Georgios, et al.
Published: (2026)
by: Alexopoulos, Georgios, et al.
Published: (2026)
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
by: Yang, Ruozhao, et al.
Published: (2026)
by: Yang, Ruozhao, et al.
Published: (2026)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
A Survey of Web Application Security Tutorials
by: Chembakottu, Bhagya, et al.
Published: (2026)
by: Chembakottu, Bhagya, et al.
Published: (2026)
Unsupervised Binary Code Translation with Application to Code Similarity Detection and Vulnerability Discovery
by: Ahmad, Iftakhar, et al.
Published: (2024)
by: Ahmad, Iftakhar, et al.
Published: (2024)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
by: Lingxiang, Wang, et al.
Published: (2025)
by: Lingxiang, Wang, et al.
Published: (2025)
Exposing Go's Hidden Bugs: A Novel Concolic Framework
by: Gorna, Karolina, et al.
Published: (2025)
by: Gorna, Karolina, et al.
Published: (2025)
Broken Quantum: A Systematic Formal Verification Study of Security Vulnerabilities Across the Open-Source Quantum Computing Simulator Ecosystem
by: Blain, Dominik
Published: (2026)
by: Blain, Dominik
Published: (2026)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
by: Li, Zhen, et al.
Published: (2024)
by: Li, Zhen, et al.
Published: (2024)
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
Fine-grained Data Access Control for Collaborative Process Execution on Blockchain
by: Marangone, Edoardo, et al.
Published: (2022)
by: Marangone, Edoardo, et al.
Published: (2022)
Vulnerability-Hunter: An Adaptive Feature Perception Attention Network for Smart Contract Vulnerabilities
by: Chen, Yizhou
Published: (2024)
by: Chen, Yizhou
Published: (2024)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
EDEFuzz: A Web API Fuzzer for Excessive Data Exposures
by: Pan, Lianglu, et al.
Published: (2023)
by: Pan, Lianglu, et al.
Published: (2023)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
by: Zhang, Fangyuan, et al.
Published: (2024)
by: Zhang, Fangyuan, et al.
Published: (2024)
Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
by: Wang, Weizhe, et al.
Published: (2025)
by: Wang, Weizhe, et al.
Published: (2025)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Revisiting Vulnerability Patch Identification on Data in the Wild
by: Irsan, Ivana Clairine, et al.
Published: (2026)
by: Irsan, Ivana Clairine, et al.
Published: (2026)
Smart Contract Fuzzing Towards Profitable Vulnerabilities
by: Kong, Ziqiao, et al.
Published: (2025)
by: Kong, Ziqiao, et al.
Published: (2025)
Root-Cause-Driven Automated Vulnerability Repair
by: Wang, Hulin, et al.
Published: (2026)
by: Wang, Hulin, et al.
Published: (2026)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
Fast and Accurate Silent Vulnerability Fix Retrieval
by: Liu, Xueqing, et al.
Published: (2025)
by: Liu, Xueqing, et al.
Published: (2025)
Detecting Protracted Vulnerabilities in Open Source Projects
by: Sridharkumar, Arjun, et al.
Published: (2026)
by: Sridharkumar, Arjun, et al.
Published: (2026)
An Empirical Study of Vulnerability Handling Times in CPython
by: Ruohonen, Jukka
Published: (2024)
by: Ruohonen, Jukka
Published: (2024)
How Effective Are Neural Networks for Fixing Security Vulnerabilities
by: Wu, Yi, et al.
Published: (2023)
by: Wu, Yi, et al.
Published: (2023)
Similar Items
-
Fuzzing Frameworks for Server-side Web Applications: A Survey
by: Dharmaadi, I Putu Arya, et al.
Published: (2024) -
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025) -
Exposing and Defending Membership Leakage in Vulnerability Prediction Models
by: Liao, Yihan, et al.
Published: (2025) -
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025) -
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
by: Yang, Guan-Yan, et al.
Published: (2025)