PHPã§èªãã¼ã¸ããèªãã¼ã¸ã¸é·ç§»ããåä½ããããã¨ããAã¿ã°ãFORMã¿ã°ã«$_SERVER['PHP_SELF']ã使ãæ¹æ³ãããã¾ãã Aã¿ã°ã«ä½¿ãå ´å <a href="<?php echo $_SERVER['PHP_SELF']; ?>"> FORMã¿ã°ã«ä½¿ãå ´å <form method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>"> ããããã®ãããªç®çã§$_SERVER['PHP_SELF']ã使ãã¨ãã«ã¯æ°ãã¤ããã»ããããã§ãã XSS(ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°)ã¨ããã»ãã¥ãªãã£ã¼ãã¼ã«ã«ãªãã¾ãã CakePHPãZend Frameworkãªã©mod_rewriteã使ã£ã¦ããã¨ãã§ãã ä¾ãã°æ¬¡ã®ãããªURL http://example.com/hoge.php/"><script>alert('
{{#tags}}- {{label}}
{{/tags}}