Have things changed now? An empirical study on input validation vulnerabilities in web applications