IE8ã®XSSãã£ã«ã¿ã¯ãWebã¢ããªã«XSSèå¼±æ§ããã£ãã¨ãã¦ãããããçºåããå¯è½æ§ãæ¸ããã¦ããããã®ã§ãã ãããããã®XSSãã£ã«ã¿ãè£ç®ã«åºããããªãã¨ãããã¾ãã ä¾ãã°ã以ä¸ã®ãããªéçãªHTMLãã¡ã¤ã«ï¼test.htmlï¼ãä½ã£ã¦Webãµã¼ãã«ããã¾ãã <h3>ie8 test</h3> <!-- 1 --> <script> var u=document.URL; </script> <!-- 2 --> <script> u=u.replace(/&/g,'&').replace(/</g,'<'); </script> <!-- 3 --> <script> document.write('URL:'+u); </script> ä¸ã®ãã¼ã¸ã¯éçãªãã¼ã¸ã§ãDOM Based XSSã®èå¼±æ§ãããã¾ãããã§ããã被害è ã®ã¦ã¼ã¶ãIE8ã使ã£ã¦ãã
{{#tags}}- {{label}}
{{/tags}}