Skip to main content
x

Programming Language တစ်ခုဖြစ်သော Ruby on Rails သည် User Input များကို ကောင်းမွန်စွာ Validate မလုပ်နိုင်

Programming Language တစ်ခုဖြစ်သော Ruby on Rails သည် User Input များကို ကောင်းမွန်စွာ Validate မလုပ်နိုင်သောကြောင့် Cross-Site Scriptiing Vulnerability ရှိနေကြောင်း Security Focus တွင်ထုတ်ပြန်ထားသည်။
Attacker သည် ၄င်းအားနည်းချက်ကို အသုံးပြုကာ Arbitrary Code ကို Browser ထဲတွင် execute လုပ်နိုင်ကာ affected website ထဲရှိ User Information များကို ကြည့်ရှုနိုင်ကြောင်း ကြေငြာခဲ့သည်။
ထို့ပြင် Cookie-Based Authentications ကိုလည်းရယူနို်င်ကာ အခြား Attack များကို ဖြစ်ပေါ်စေနိုင်သည်ဟုကြေငြာခဲ့သည်။
အသေးစိတ်အချက်အလက်များကိုအောက်ပါ Link တွင်ဝင်ရောက်ကြည့်ရှုနိုင်သည်။

http://www.securityfocus.com/bid/64077/discuss