ãããã°ããªããä¸è¨ãæè¦ãã¾ããã UTF-7 XSS Cheat Sheet Specify charset clearly (HTTP header is recommended) Don't place the text attacker can control before <meta> Specify recognizable charset name by browser. ä¸è¨ã®ãããªå¯¾çãå¿ è¦ã¨ãããµã¤ãã§ã¯æ¾ç½®ãã¦ããã°UTF-7ç³»ã®XSS以å¤ã§ãXSSã®å±éºæ§ã¯åå¨ãããã¨æããã¾ããã§ãã®ã§â¦ ãã¨ãã¤ãã¬ã¿ããã®åå¿ãèªã¿ãªããæã£ããã§ãããä¸è¬çãªXSS対çã§ã<ãã>ããªã©ãã<ãã>ãã«ã¨ã¹ã±ã¼ãããããã«ãæ©æ¢°çã«ã+ããã+ãã«ã¨ã¹ã±ã¼ããã¦ããã°ãä¸ãä¸ã®ã¨ãã§ãUTF-7ã«ããXSSãé²ãããããªæ°ããããã§ããã©ããã¾ãæ·±ã
{{#tags}}- {{label}}
{{/tags}}