Detection and Prevention of Code Injection Attacks on HTML5-based Apps