çããã¯åãã¹ã¯ãªããã¸ã®ãªã³ã¯ãè²¼ãæãã©ã®æ§ã«è¨è¿°ãã¦ãã¾ããï¼ $_SERVER['PHP_SELF']ãç¨ãããã¨ãããã®ã§ã¯ãªãã§ããããããããç´æ¥ç¨ ãããã¨ã¯å±éºã§ãããªããªãã°ã$_SERVER['PHP_SELF']ã«ã¯ã¯ãã¹ãµã¤ãã»ã¹ ã¯ãªããã£ã³ã°ï¼XSSï¼èå¼±æ§ãåå¨ããããã§ãã $_SERVER['PHP_SELF']ã¯ãã°ãã°æ¬¡ã®ããã«ä½¿ããã¾ãã <form method="post" action="<?php echo $_SERVER['PHP_SELF'] ?>"> ãã®ãã¼ã¸ï¼ããã§ã¯http:/www.example.jp/example.phpï¼ã¸ä¸è¨ã®æ§ã«ãªã³ã¯ ãè²¼ããã¯ãªãã¯ãã¦ã¿ã¦ä¸ããã <a href="http://www.example.jp/ example.php/%22%3E%3Cscript%3Ealert(%27XS
{{#tags}}- {{label}}
{{/tags}}