RT Conference Proceedings T1 A multi-agent scanner to detect stored-XSS vulnerabilities A1 Galán, Eduardo A1 Alcaide Raya, Almudena A1 Orfila Díaz-Pabon, Agustín A1 Blasco Alís, Jorge AB The cross-site scripting (XSS) has become a common vulnerability of many web sites and web applications. XSS consists in the exploitation of input validation flaws, with the purpose of injecting arbitrary script code which is later executed at the web browser of the victim. One interesting possibility to prevent this type of vulnerability is the use of vulnerability scanners. However, current scanners are capable of detecting just one of the two main modalities of XSS attacks. This paper introduces a novel multi–agent system for the automated scanning of web sites to detect the presence of XSS vulnerabilities exploitable by an stored–XSS attack. The rate of detection of the system is evaluated in two different scenarios. PB IEEE SN 978-1-4244-8862-9 YR 2010 FD 2010-11 LK https://hdl.handle.net/10016/9997 UL https://hdl.handle.net/10016/9997 LA eng NO Proceeding of: 2010 International Conference for Internet Technology and Secured Transactions (ICITST), 8 to 11 November 2010 London, England, United Kingdom NO This work has been partially supported by CDTI (Ministerio de Industria, Turismo y Comercio of Spain) in collaboration with Telefonica I+D, Project SEGUR@ with reference CENIT-2007 2004 DS e-Archivo RD 30 jun. 2024