From 0f8da57b54af2e156f8cf0bf5baf3f58bdd441f1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Mon, 21 Nov 2005 12:46:10 +0000 Subject: [PATCH] Avoid XSS on HTTP_HOST. --- ChangeLog | 1 + index.php | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/ChangeLog b/ChangeLog index 66599fe2a..64c894389 100755 --- a/ChangeLog +++ b/ChangeLog @@ -15,6 +15,7 @@ $Source$ * main.php, libraries/select_server.lib.php, libraries/auth/cookie.auth.lib.php: Escape verbose server name (bug #1362671). + * index.php: Avoid XSS on HTTP_HOST. 2005-11-20 Marc Delisle ### 2.7.0-rc1 released diff --git a/index.php b/index.php index f7a0a1d13..d09f5101a 100644 --- a/index.php +++ b/index.php @@ -129,7 +129,7 @@ header('Content-Type: text/html; charset=' . $GLOBALS['charset']); -phpMyAdmin <?php echo PMA_VERSION; ?> - <?php echo $HTTP_HOST; ?> +phpMyAdmin <?php echo PMA_VERSION; ?> - <?php echo htmlspecialchars($HTTP_HOST); ?>