ã¨ã°ã¼ã¯ãã£ããµã㪠PHPã®èå¼±æ§CVE-2018-17082ã¯XSSã¨ãã¦å ±åããã¦ããããç¾å®ã«ã¯XSSã¨ãã¦ã®æ»æçµè·¯ã¯ãªããä¸æ¹ãApacheã®mod_cacheã«ãããã£ãã·ã¥æ©è½ãæå¹ã«ãã¦ãããµã¤ãã§ã¯ããã£ãã·ã¥æ±æã¨ããæ»æãåããå¯è½æ§ãããã æ¦è¦ PHPã®ç¾å¨ãµãã¼ãä¸ã®ãã¹ã¦ã®ãã¼ã¸ã§ã³ã«ã¤ãã¦ãXSSèå¼±æ§CVE-2018-17082ãä¿®æ£ããã¾ããã以ä¸ã¯å¯¾å¿ãã¼ã¸ã§ã³ã§ãããããããåã®ãã¹ã¦ã®ãã¼ã¸ã§ã³ãå½±é¿ãåãã¾ãããã ããApacheã¨ã®æ¥ç¶ã«Apache2handlerãç¨ãã¦ããå ´åã«éãã¾ãã PHP 5.6.38 PHP 7.0.32 PHP 7.1.22 PHP 7.2.10 PHP 5.5以åã対象ã§ããããããã¯èå¼±æ§ã¯ä¿®æ£ããã¦ãã¾ããã èå¼±æ§ãåç¾ããã¦ã¿ã ãã®èå¼±æ§ã®PoCã¯ãå½åé¡ã®ãã°ã¬ãã¼ãã«ããã¾ãã PHP ::
{{#tags}}- {{label}}
{{/tags}}