{"id":"W3124662913","doi":"10.1109/icdis50059.2020.00012","title":"An Analysis of Effectiveness of Black-Box Web Application Scanners in Detection of Stored SQL Injection and Stored XSS Vulnerabilities","year":2020,"lang":"en","type":"article","venue":"","topic":"Web Application Security Vulnerabilities","field":"Computer Science","cited_by":11,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University of Edmonton","funders":"","keywords":"Cross-site scripting; Computer science; SQL injection; Scripting language; Black box; Web application; Database; JavaScript; SQL; Testbed; World Wide Web; Operating system; Web page; Web application security; Artificial intelligence; Web development; Query by Example","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001638475,0.0004872518,0.0005232912,0.001475362,0.0002408667,0.0005393532,0.0004212439,0.0005415255,0.001066286],"category_scores_gemma":[0.005631253,0.0001843912,0.0004262021,0.0006559054,0.0003213446,0.001478942,0.0002851154,0.0002850381,0.0002944469],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0004680029,"about_ca_system_score_gemma":0.0002966585,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001514535,"about_ca_topic_score_gemma":0.001348001,"domain_scores_codex":[0.9980586,0.0005027446,0.000171126,0.0003431672,0.000694222,0.0002301632],"domain_scores_gemma":[0.9857712,0.009603065,0.001158129,0.001014615,0.002119857,0.0003332777],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.009152734,0.002566283,0.2571476,0.001125272,0.0006983312,0.00155254,0.0007448987,0.07386933,0.2800407,0.001912126,0.00331844,0.3678718],"study_design_scores_gemma":[0.00008605535,0.007463197,0.3157485,0.00006096706,0.0003701034,0.001395981,0.0005111705,0.4608492,0.2111007,0.0005444764,0.001739637,0.0001300788],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9944983,0.0004039429,0.003540236,0.00002991024,0.00001024149,0.00004192465,0.0001317844,0.0003772863,0.0009663107],"genre_scores_gemma":[0.9958302,0.0001070851,0.003281897,0.00001180252,0.000004672739,0.00001209259,0.0002095774,0.00002039361,0.0005223532],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.001638475,"threshold_uncertainty_score":0.008665144,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.009062021449745111,"score_gpt":0.2501606827558739,"score_spread":0.2410986613061288,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}