Posted on: 2011/11/18 CakePHP ã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦èããï¼SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãXSSãCSRFï¼ æ¦è¦ SQLã使ã£ã¦ä¸æ£ã«ãã¼ã¿ãã¼ã¹ãæä½ããæ»æ æ»æä¾ ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããå ¥åãã¦ãã°ã¤ã³ããå¦çãããã¨ããã username 㨠password ã®çµã¿åãããããã¼ã¿ãã¼ã¹ã®ãã®ã¨ä¸è´ããã°èªè¨¼ããã¨ããä»çµã¿ã ã¨ããã SELECT * FROM users WHERE username='$username' AND password='$password' ããã§ãï¼$username: admin, $password: ' OR 'a'='aï¼ã¨å ¥åããã¨ãSQLã¯ä»¥ä¸ã®ããã«ãªãã SELECT * FROM users WHERE username='admin' AND password='' OR 'a'='a' ã
{{#tags}}- {{label}}
{{/tags}}