ãã¯ã PHP ã¾ã£ããæ¸ãã¦ãªãã®ã« PHP é¢ä¿ã®ã¨ã³ããªã°ãããå¢ãã¦ããã¨ããã®ã¯å¥å¦ãªãã®ã§ããã ãã¦ãä»å¹´ã® 2 æã« Zend Framework ããå ¬éããã以ä¸ã®ã¢ããã¤ã¶ãªã«ã¤ãã¦ã¯çæ§ãã§ã«ãã§ãã¯æ¸ã¿ã®ãã¨ã§ãããã ZF2014-01: Potential XXE/XEE attacks using PHP functions: simplexml_load_*, DOMDocument::loadXML, and xml_parse http://framework.zend.com/security/advisory/ZF2014-01 åèªèº«ã¯ Zend Framework ã使ã£ã¦ããªãã£ãã®ã§ãããã¼ãªãã XXE [1] ã¸ã®å¯¾çæ¼ããã¦ããå ´æã¨ããã£ãã®ããªã¼ãã¨ããªãã¨ãã§ããèªã¾ãã«ã¹ã«ã¼ãã¦ããã®ã§ãããæè¿ã«ãªã£ã¦èª¿ã¹ã¦ã¿ãã¨ããã©ãã
{{#tags}}- {{label}}
{{/tags}}