{"blog_title":"\u3060\u3089\u3060\u3089\u3084\u308b\u3088\u3002","version":"1.0","author_url":"https://blog.hatena.ne.jp/nagakura_eil/","provider_url":"https://hatena.blog","blog_url":"https://nagakura-eil.hatenadiary.org/","url":"https://nagakura-eil.hatenadiary.org/entry/20090419/p1","author_name":"nagakura_eil","title":"\u305d\u308d\u305d\u308dSQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306b\u3064\u3044\u3066\u3072\u3068\u3053\u3068\u8a00\u3063\u3066\u304a\u304f\u304b\u3002","published":"2009-04-19 00:00:00","type":"rich","categories":["\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3"],"provider_name":"Hatena Blog","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fnagakura-eil.hatenadiary.org%2Fentry%2F20090419%2Fp1\" title=\"\u305d\u308d\u305d\u308dSQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306b\u3064\u3044\u3066\u3072\u3068\u3053\u3068\u8a00\u3063\u3066\u304a\u304f\u304b\u3002 - \u3060\u3089\u3060\u3089\u3084\u308b\u3088\u3002\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","height":"190","width":"100%","description":"\u3061\u3087\u3063\u3068SQL Injection\u306b\u3064\u3044\u3066\u672a\u3060\u306b\u60c5\u5831\u304c\u5c11\u306a\u3044\u306e\u306b\u3044\u3089\u3064\u3044\u3066\u3044\u305f\u306e\u3067\u3002 \u3068\u3044\u3046\u304b\u5bfe\u7b56\u3070\u3063\u304b\u308a\u3067\u4f55\u304c\u3067\u304d\u307e\u3059\u3088\u30fc\u3063\u3066\u306e\u306f\u307b\u3068\u3093\u3069\u30ed\u30b0\u30a4\u30f3\u3067\u304d\u307e\u3059\u3088\u30fc\u304f\u3089\u3044\u3058\u3083\u306d\u3048\u304b\u3002 \u5177\u4f53\u7684\u306a\u653b\u6483\u65b9\u6cd5\u3082\u308f\u304b\u3089\u305a\u306b\u307c\u3093\u3084\u308a\u5bfe\u7b56\u3057\u3066\u308b\u3060\u3051\u306e\u4eba\u591a\u3044\u3088\u3046\u306a\u6c17\u304c\u3059\u308b\u306e\u3067\u3061\u3087\u3063\u3068\u653b\u6483\u65b9\u6cd5\u66f8\u3044\u3068\u304f\u3002 SQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u3063\u3066\u306a\u306b\uff1f \u30a2\u30d7\u30ea\u306e\u30e6\u30fc\u30b6\u5165\u529b\u9818\u57df\u304b\u3089SQL\u6587\u3092\u6ce8\u5165\u3055\u308c\u3066\u3057\u307e\u3046\u3053\u3068\u3002 \u30b5\u30fc\u30d0\u3067\u3053\u3046\u3044\u3046\u30b3\u30fc\u30c9\u66f8\u3044\u3066\u308b\u3068\u3001user_name\u306b\u300c' or '1'='1';#\u300d\u3068\u304b\u66f8\u304b\u308c\u3066\u7d20\u6575\u306a\u3053\u3068\u306b\u306a\u308b\u3002(mysql\u306e\u5834\u5408) String sql = \"SELECT * FROM users WHERE = \u2026","image_url":null}