çããã¯åãã¹ã¯ãªããã¸ã®ãªã³ã¯ãè²¼ãæãã©ã®æ§ã«è¨è¿°ãã¦ãã¾ããï¼ $_SERVER['PHP_SELF']ãç¨ãããã¨ãããã®ã§ã¯ãªãã§ããããããããç´æ¥ç¨ ãããã¨ã¯å±éºã§ãããªããªãã°ã$_SERVER['PHP_SELF']ã«ã¯ã¯ãã¹ãµã¤ãã»ã¹ ã¯ãªããã£ã³ã°ï¼XSSï¼èå¼±æ§ãåå¨ããããã§ãã $_SERVER['PHP_SELF']ã¯ãã°ãã°æ¬¡ã®ããã«ä½¿ããã¾ãã <form method="post" action="<?php echo $_SERVER['PHP_SELF'] ?>"> ãã®ãã¼ã¸ï¼ããã§ã¯http:/www.example.jp/example.phpï¼ã¸ä¸è¨ã®æ§ã«ãªã³ã¯ ãè²¼ããã¯ãªãã¯ãã¦ã¿ã¦ä¸ããã <a href="http://www.example.jp/ example.php/%22%3E%3Cscript%3Ealert(%27XS
![13. $_SERVER['PHP_SELF']ã¨XSSèå¼±æ§](https://cdn-ak-scissors.b.st-hatena.com/image/square/bed39b5962a5d552c95b6d796db8f55e72d32943/height=288;version=1;width=512/https%3A%2F%2Fxtech.nikkei.com%2Fimages%2Fn%2Fxtech%2F2020%2Fogp_nikkeixtech_hexagon.jpg%3F20220512)
{{#tags}}- {{label}}
{{/tags}}