IEBlog : IE8 Security Part IV: The XSS Filter ã«ã¤ãã¦ãè¨äºãæ¸ãã David Ross ããã«ç¿»è¨³è¨±å¯ããããã¾ããã®ã§ã訳ãã¦ã¿ã¾ããã誤訳ãææãããã¾ãããã¬ã³ã¬ã³çªã£è¾¼ã¿ããé¡ããããã¾ã(ä»ã®è¨äºãæéãã¨ã£ã¦è¨³ãã¦ãããã¨æãã¾ã)ãå½ç¶ãªãããããã¯ç§ãç§çã«è¨³ãããã®ã§ãããMicrosoftã«ããå ¬å¼ãªç¿»è¨³/è¦è§£ã§ã¯ããã¾ããã (訳注追å ) ãreflected / Type-1 XSSãã¨ããã®ã¯ãæ»æã³ã¼ãã被害è ããã®ãªã¯ã¨ã¹ãèªèº«ã«å«ã¾ããã¿ã¤ãã®XSSã§ããµã¼ãå´ã®ã¢ããªã±ã¼ã·ã§ã³ã§ã¦ã¼ã¶ããã®ãªã¯ã¨ã¹ãã«å«ã¾ããæ»æã³ã¼ãããåå°çãã«è¿ããããªç¨®é¡ã®XSSã§ããå ¸åçã«ã¯ã"><script>...ãã®ãããªèªãæ¤ç´¢ããã¨ãã« <input type="text" value=""><script>..."
{{#tags}}- {{label}}
{{/tags}}