Matches in SemOpenAlex for { <https://semopenalex.org/work/W3126695527> ?p ?o ?g. }
Showing items 1 to 94 of
94
with 100 items per page.
- W3126695527 abstract "Nearly every second website is using a Content Management System (CMS) such as WordPress, Drupal, and Joomla. These systems help to create and modify digital data, typically within a collaborative environment. One common feature is to enrich their functionality by using extensions. Popular extensions allow developers to easily include payment gateways, backup tools, and social media components. Due to the extended functionality, it is not surprising that such an expansion of complexity implies a bigger attack surface. In contrast to CMS core systems, extensions are usually not considered during public security audits. However, a Cross-Site Scripting (XSS) or SQL injection (SQLi) attack within an activated extension has the same effect on the security of a CMS as the same issue within the core itself. Therefore, vulnerabilities within extensions are a very attractive tool for malicious parties. We study the security of CMS extensions using the example Joomla; one of the most popular systems. We discovered that nearly every second installation of such a system also includes Joomla's official top-10 rated extensions as a per se requirement. Moreover, we have detected that every single extension of the official top-10 rated extensions is vulnerable to XSS and 30% of them against SQLi. We show that our findings are not only relevant to Joomla; two of the analyzed extensions are available within systems like WordPress or Drupal, and introduce the same vulnerabilities. Finally, we pinpoint mitigation strategies that can be realized within extensions to achieve the same security level as the core CMS." @default.
- W3126695527 created "2021-02-15" @default.
- W3126695527 creator A5034652773 @default.
- W3126695527 creator A5039361952 @default.
- W3126695527 creator A5060434302 @default.
- W3126695527 creator A5091741421 @default.
- W3126695527 date "2021-02-05" @default.
- W3126695527 modified "2023-10-04" @default.
- W3126695527 title "Over 100 Bugs in a Row: Security Analysis of the Top-Rated Joomla Extensions." @default.
- W3126695527 cites W1429964360 @default.
- W3126695527 cites W1969354810 @default.
- W3126695527 cites W2049214202 @default.
- W3126695527 cites W2060218972 @default.
- W3126695527 cites W2177614278 @default.
- W3126695527 cites W2288652276 @default.
- W3126695527 cites W2323558338 @default.
- W3126695527 cites W2493145165 @default.
- W3126695527 cites W2510134782 @default.
- W3126695527 cites W2619020149 @default.
- W3126695527 cites W2753884237 @default.
- W3126695527 cites W2888830098 @default.
- W3126695527 cites W2901089484 @default.
- W3126695527 cites W2954467127 @default.
- W3126695527 hasPublicationYear "2021" @default.
- W3126695527 type Work @default.
- W3126695527 sameAs 3126695527 @default.
- W3126695527 citedByCount "1" @default.
- W3126695527 countsByYear W31266955272021 @default.
- W3126695527 crossrefType "posted-content" @default.
- W3126695527 hasAuthorship W3126695527A5034652773 @default.
- W3126695527 hasAuthorship W3126695527A5039361952 @default.
- W3126695527 hasAuthorship W3126695527A5060434302 @default.
- W3126695527 hasAuthorship W3126695527A5091741421 @default.
- W3126695527 hasConcept C111919701 @default.
- W3126695527 hasConcept C136764020 @default.
- W3126695527 hasConcept C150451098 @default.
- W3126695527 hasConcept C164120249 @default.
- W3126695527 hasConcept C194222762 @default.
- W3126695527 hasConcept C199360897 @default.
- W3126695527 hasConcept C2778029271 @default.
- W3126695527 hasConcept C2780945871 @default.
- W3126695527 hasConcept C35578498 @default.
- W3126695527 hasConcept C38652104 @default.
- W3126695527 hasConcept C39569185 @default.
- W3126695527 hasConcept C41008148 @default.
- W3126695527 hasConcept C59241245 @default.
- W3126695527 hasConcept C61423126 @default.
- W3126695527 hasConcept C77088390 @default.
- W3126695527 hasConcept C79373723 @default.
- W3126695527 hasConcept C97854310 @default.
- W3126695527 hasConceptScore W3126695527C111919701 @default.
- W3126695527 hasConceptScore W3126695527C136764020 @default.
- W3126695527 hasConceptScore W3126695527C150451098 @default.
- W3126695527 hasConceptScore W3126695527C164120249 @default.
- W3126695527 hasConceptScore W3126695527C194222762 @default.
- W3126695527 hasConceptScore W3126695527C199360897 @default.
- W3126695527 hasConceptScore W3126695527C2778029271 @default.
- W3126695527 hasConceptScore W3126695527C2780945871 @default.
- W3126695527 hasConceptScore W3126695527C35578498 @default.
- W3126695527 hasConceptScore W3126695527C38652104 @default.
- W3126695527 hasConceptScore W3126695527C39569185 @default.
- W3126695527 hasConceptScore W3126695527C41008148 @default.
- W3126695527 hasConceptScore W3126695527C59241245 @default.
- W3126695527 hasConceptScore W3126695527C61423126 @default.
- W3126695527 hasConceptScore W3126695527C77088390 @default.
- W3126695527 hasConceptScore W3126695527C79373723 @default.
- W3126695527 hasConceptScore W3126695527C97854310 @default.
- W3126695527 hasLocation W31266955271 @default.
- W3126695527 hasOpenAccess W3126695527 @default.
- W3126695527 hasPrimaryLocation W31266955271 @default.
- W3126695527 hasRelatedWork W128715817 @default.
- W3126695527 hasRelatedWork W1527892 @default.
- W3126695527 hasRelatedWork W1598325486 @default.
- W3126695527 hasRelatedWork W1852822942 @default.
- W3126695527 hasRelatedWork W1983343365 @default.
- W3126695527 hasRelatedWork W2146558214 @default.
- W3126695527 hasRelatedWork W2184626283 @default.
- W3126695527 hasRelatedWork W2323558338 @default.
- W3126695527 hasRelatedWork W2504194819 @default.
- W3126695527 hasRelatedWork W2523390657 @default.
- W3126695527 hasRelatedWork W2550028013 @default.
- W3126695527 hasRelatedWork W2616617889 @default.
- W3126695527 hasRelatedWork W2771281827 @default.
- W3126695527 hasRelatedWork W2891060526 @default.
- W3126695527 hasRelatedWork W2948532510 @default.
- W3126695527 hasRelatedWork W2989759921 @default.
- W3126695527 hasRelatedWork W3014530263 @default.
- W3126695527 hasRelatedWork W3168881492 @default.
- W3126695527 hasRelatedWork W3211215414 @default.
- W3126695527 hasRelatedWork W2765202860 @default.
- W3126695527 isParatext "false" @default.
- W3126695527 isRetracted "false" @default.
- W3126695527 magId "3126695527" @default.
- W3126695527 workType "article" @default.