Abstract: Traditional black-box fuzzing techniques for web applications suffer from limited code coverage and fail to detect vulnerabilities that depend on specific client-side logic, multi-step ...