SQLãç¨ãã¦ãã¼ã¿ãã¼ã¹ãæ±ãWebã¢ããªã±ã¼ã·ã§ã³ã¯ãSQLæ³¨å ¥ã許ããªãããã«ããå¿ è¦ããããSQLæ³¨å ¥æ»æ対çã®ãã¡ãã¾ãã¯å®è£ ã«ããã対çã«ã¤ãã¦è¿°ã¹ãã æèã«å¿ããç¹æ®è¨å·å¯¾çã¯ã³ãã³ãæ³¨å ¥æ»æ対çã¨åæ§ã§ãããå ãã¦ãããªãã¢ã¼ãã¹ãã¼ãã¡ã³ãã®ä½¿ç¨ãè¨èªã®é¸æã«ãã対çã説æããã ãSQLæ³¨å ¥ï¼SQL injectionï¼ãã¯ããã©ã¡ã¼ã¿ãåãè¾¼ãã§SQLæãçµã¿ç«ã¦ãå ´åããã®ãã©ã¡ã¼ã¿ã«ç¹æ®è¨å·ï¼è¨å·ï¼ãå«ã¾ããSQLã³ãã³ããä¸ãããã¨ã«ãã£ã¦ããã¼ã¿ãã¼ã¹ã®ä¸æ£æä½ãå¯è½ã¨ãªã£ã¦ãã¾ãåé¡ã§ããã åèï¼ CWE-89: Improper Neutralization of Special Elements used in an SQL Commandï¼æ¥æ¬èªè¨³ï¼ SQLæ³¨å ¥æ»æã®ã¡ã«ããºã ããã«ã次ã®ãããªSQLæã使ç¨ãããã°ã¤ã³å¤å®ããã°ã©ã ãããã¨ãã
{{#tags}}- {{label}}
{{/tags}}