æè¿èªå® å¼ããããã§æéãã§ããã®ã§ãYouTubeåç»ãæ稿ããããã«ãªãã¾ãããã¿ããªè¦ã¦ãã¼ã 徳丸浩ã®ã¦ã§ãã»ãã¥ãªãã£è¬åº§ ãããªãã¨ã§ã次ã®åç»ã¯ããæ°ã«å ¥ãã®PHPã®èå¼±æ§ CVE-2018-17082 ãåãä¸ãããã¨æã£ããã§ããã表åãXSSã§åºã¦ãããã©ãéåºããã®ããã³ãã«ãããããã«ãå®ã¯HTTP Request Smuggling(HRS)ã ã¨ãããã¤ã§ããã§ããä¸æºåã§ããããã¦èª¿ã¹ã¦ããã¨ããªããããåãããªãæåãã¯ã©ã¯ã©ã¨åºã¦ããããªããããããããCVE-2018-17082 å ¨ç¶åãããªããåã¯æ°åã§Â CVE-2018-17082 ãæ±ã£ã¦ãã⦠ã§ãéã«æ´çããã¨ã以ä¸ã®ãããªæããªãã§ãã å¤ãç°å¢ã ã¨CVE-2018-17082ã¯çºç¾ããªãï¼2015年以åï¼ å°ãå¤ãç°å¢ã ã¨CVE-2018-17082ã¯çºç¾ãã æ°ããç°å¢ã ã¨CVE-2018
{{#tags}}- {{label}}
{{/tags}}