Research Article

Large-Scale Analysis of Remote Code Injection Attacks in Android Apps

Table 2

Results of Google Play dataset (). All vulnerable apps were manually confirmed.

Category Type Number of potentially vuln apps Number of flagged vuln apps

File overwrite vulnerabilitiesUnsafe ZIP75 (1.5%)49
Unsafe Content-Disposition15 (0.3%)0

= static HTTP URL + dynamic URL; = − dynamic URL.