๊ด€๋ฆฌ ๋ฉ”๋‰ด

bom's happy life

[JSP] ๋ฐ์ดํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ์ถœ๋ ฅํ•˜๊ธฐ - excapeXml ํ•จ์ˆ˜, <c:out>ํƒœ๊ทธ ์‚ฌ์šฉ ๋ณธ๋ฌธ

Deveolpment Study๐Ÿ—‚๏ธ/JSP

[JSP] ๋ฐ์ดํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ์ถœ๋ ฅํ•˜๊ธฐ - excapeXml ํ•จ์ˆ˜, <c:out>ํƒœ๊ทธ ์‚ฌ์šฉ

bompeach 2023. 10. 11. 13:33
XSS๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ๋ฐ์ดํ„ฐ ์ถœ๋ ฅํ•˜๊ธฐ

 

1. ${fn:escapeXml()} ํ•จ์ˆ˜ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ์ถœ๋ ฅํ•˜๊ธฐ, XSS๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ์œ ์ง€๋œ๋‹ค.

</p>
<c:if test="${!empty resultInfo}">
    <p class="p_title">${fn:escapeXml(resultInfo.title)}</p>
    <p class="p_txt">${fn:escapeXml(resultInfo.content)}</p>
</c:if>
<td colspan="2" class="cont_area">
   <textarea class="w98p" id="content" name="content" title="๋‚ด์šฉ">${fn:escapeXml(board.content)}</textarea>
</td>

 

2. <c:out> ํƒœ๊ทธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•ˆ์ „ํ•˜๊ฒŒ ์ถœ๋ ฅํ•˜๊ธฐ , XSS๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ์•ˆ์ „ํ•˜๊ฒŒ ์œ ์ง€๋œ๋‹ค.

</p>
<c:if test="${!empty resultInfo}">
    <p class="p_title"><c:out value="${resultInfo.title}" /></p>
    <p class="p_txt"><c:out value="${resultInfo.content}" /></p>
</c:if>
<td colspan="2" class="cont_area">
   <textarea class="w98p" id="content" name="content" title="๋‚ด์šฉ"><c:out value="${board.content}" /></textarea>
</td>