ã¨æ¸ãã¨ããå±éºãªæåãã¨ã¿ãªããã "expression" 㨠"cookie" ããµãã¿ã¤ãºããã¦ä»¥ä¸ã®ããã«ãªãã¾ãã
ã¨æ¸ãã¨ããå±éºãªæåãã¨ã¿ãªããã "expression" 㨠"cookie" ããµãã¿ã¤ãºããã¦ä»¥ä¸ã®ããã«ãªãã¾ãã
ååã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ãçªãæ»æã®å¯¾çã¨ãã¦ã®HTMLã¨ã³ã³ã¼ãã®æå¹æ§ãè¿°ã¹ãããã ï¼HTMLã¨ã³ã³ã¼ãã ãã§ã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æãå®å ¨ã«é²å¾¡ãããã¨ã¯ã§ããªããããã§ä»åã¯ï¼HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãã¿ã¤ãã®ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æã®æå£ã¨ï¼ãã®å¯¾çã«ã¤ãã¦è§£èª¬ããã HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãæ»æã«ã¯ï¼æ¬¡ã®ãããªãã®ãããã ã¿ã°æåã®å ¥åã許容ãã¦ããå ´åï¼Webã¡ã¼ã«ï¼ããã°ãªã©ï¼ CSSï¼ã«ã¹ã±ã¼ãã£ã³ã°ã»ã¹ã¿ã¤ã«ã·ã¼ãï¼ã®å ¥åã許容ãã¦ããå ´åï¼ããã°ãªã©ï¼ æåã³ã¼ããæ示ãã¦ããªãã±ã¼ã¹ã§UTF-7æåã³ã¼ãã«ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° <SCRIPT>ã®å 容ãåçã«çæãã¦ããå ´å Aã¿ã°ãªã©ã®URLãåçã«çæãã¦ããå ´åæ³¨ï¼ ä»¥ä¸ã§ã¯ï¼HTMLã¿ã°ãCSSã®å ¥åã許容ãã¦ããå ´åã¨ï¼æåã³ã¼ããæ
IE ã«ããã "expression" ã®éå°æ¤åºã«ãã XSS ã® èªå 2006-08-31-1: [Security] http://archive.openmya.devnull.jp/2006.08/msg00369.html IE ã§ã¯ expression(å¼) ãã¹ã¿ã¤ã«ã·ã¼ãå ã§è¨è¿°ãããã¨ã§ JavaScript ãè¨è¿°ãããã¨ãã§ããã®ã¯æåã§ããï¼ IE ã«ãã expression ã®æ¤åºããããéå°ã§ XSS ãå¼ãèµ·ãããããã¨ãããã¨ãããï¼ å®æ åç §ãã³ã¡ã³ãã®æ¿å ¥ï¼Unicode æåï¼å ¨è§æåã§è¨è¿°ãã¦ã expression ã¨ãã¦æ¤åºãããï¼ è©³ç´°ã¯ï¼ä¸è¨ãµã¤ãããå¼ç¨ï¼ IE ã§ã¯ã以ä¸ã®ãããªã¹ã¿ã¤ã«ãè¨è¿°ãããã¨ã§ãJavaScript ãåä½ããã ãã¨ãå¯è½ã§ãã 1) <style>ãããã¯å ã§ã®å®ç¾© <style>input { l
ã¯ã¦ãªããã°ã®ãã«ãã§ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}