èå¼±æ§è¨ºæããã£ã¦ããã¨ããã¾ã«type=hiddenã®inputè¦ç´ ã«XSSããããã©ãç¾å®çãªæ»æã«ã¯è³ããªããã®ã«ã¶ã¡ããããã¨ãããã¾ãããµã³ãã«ã³ã¼ãã以ä¸ã«ç¤ºãã¾ãã <body> å ¥å確èªããé¡ããã¾ãã <?php echo htmlspecialchars($_GET['t']); ?><br> <form action='submit.php'> <input type='hidden' name='t' value='<?php echo htmlspecialchars($_GET['t']); ?>'> <input type='submit'> </body> æ£å¸¸ç³»ã®å¼ã³åºãã¯ä¸è¨ã®ããã«ãªãã¾ãã http://example/hidden-xss.php?t=yamada HTMLã½ã¼ã¹ã¯ä¸è¨ã®éãã§ãã <body> å ¥å確èªããé¡ããã¾ãã yamad
{{#tags}}- {{label}}
{{/tags}}