fixed possible SQL injection using database name

This commit is contained in:
Sebastian Mendel
2007-11-09 07:41:47 +00:00
parent c18c6ca27f
commit 01574baa55
2 changed files with 4 additions and 1 deletions

View File

@@ -5,6 +5,9 @@ phpMyAdmin - ChangeLog
$Id$ $Id$
$HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyAdmin/ChangeLog $ $HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyAdmin/ChangeLog $
2.11.2.1 (not yet released)
- fixed possible SQL injection using database name
2.11.2.0 (2007-10-27) 2.11.2.0 (2007-10-27)
- patch #1791576 HTTP auth: support REDIRECT_REMOTE_USER, thanks to Allard - patch #1791576 HTTP auth: support REDIRECT_REMOTE_USER, thanks to Allard
+ [lang] Serbian update, thanks to Mihailo Stefanovic + [lang] Serbian update, thanks to Mihailo Stefanovic

View File

@@ -2032,7 +2032,7 @@ if (empty($adduser) && (! isset($checkprivs) || ! strlen($checkprivs))) {
. PMA_convert_using('`Db`') . ' AS `Db`, ' . PMA_convert_using('`Db`') . ' AS `Db`, '
. $list_of_privileges . $list_of_privileges
.' FROM `mysql`.`db`' .' FROM `mysql`.`db`'
.' WHERE ' . PMA_convert_using($checkprivs, 'quoted') .' WHERE ' . PMA_convert_using(PMA_sqlAddslashes($checkprivs), 'quoted')
.' LIKE ' . PMA_convert_using('`Db`') .' LIKE ' . PMA_convert_using('`Db`')
.' AND NOT (' . $list_of_compared_privileges. ')) ' .' AND NOT (' . $list_of_compared_privileges. ')) '
.'UNION ' .'UNION '