Author(s): Johannes Dahse, Thorsten Holz

Date: 22 Feb 2014

Associated Event: NDSS Symposium 2014


PHP is the most popular and diverse scripting language on the Web. We introduce a new static code analyzer that precisely models built-in PHP features and their interaction. Our evaluation shows that this is the key for vulnerability detection in modern applications.