{"type":"rich","version":"1.0","provider_name":"Hatena Blog","blog_url":"https://ripjyr.hatenablog.com/","title":"Secunia - Advisories - Apache \"Expect\" Header Cross-Site Scripting Vulnerability","height":"190","provider_url":"https://hatena.blog","author_url":"https://blog.hatena.ne.jp/ripjyr/","blog_title":"ripjyr's blog","author_name":"ripjyr","width":"100%","image_url":null,"published":"2006-07-26 19:45:03","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fripjyr.hatenablog.com%2Fentry%2F20060726%2F1153910703\" title=\"Secunia - Advisories - Apache &quot;Expect&quot; Header Cross-Site Scripting Vulnerability - ripjyr&#39;s blog\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","url":"https://ripjyr.hatenablog.com/entry/20060726/1153910703","categories":["\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3"],"description":"Expect:\u30d8\u30c3\u30c0\u3092\u4f7f\u3063\u305f\u3082\u306e\u304c\u30b5\u30cb\u30bf\u30a4\u30ba\u3055\u308c\u305a\u306b\u30e6\u30fc\u30b6\u30fc\u306b\u8fd4\u308b\u305d\u3046\u3067\u3059\u3002 Input passed to the \"Expect:\" header is not properly sanitised before being returned to users. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site. \u53e4\u3044\u30d0\u30fc\u30b8\u30e7\u30f3\u306b\u306e\u307f\u5f71\u97ff\u6709\u308a\u304b\u30fb\u30fb\u30fb Update to version 1.3.\u2026"}