Fixed possible code injection incase session variables are compromised, see PMASA-2011-6
This commit is contained in:
@@ -3,6 +3,7 @@ phpMyAdmin - ChangeLog
|
||||
|
||||
3.4.3.1 (not yet released)
|
||||
- [security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-5
|
||||
- [security] Fixed possible code injection incase session variables are compromised, see PMASA-2011-6
|
||||
|
||||
3.4.3.0 (2011-06-27)
|
||||
- bug #3311170 [sync] Missing helper icons in Synchronize
|
||||
|
@@ -39,7 +39,7 @@ class ConfigGenerator
|
||||
if ($cf->getServerCount() > 0) {
|
||||
$ret .= "/* Servers configuration */$crlf\$i = 0;" . $crlf . $crlf;
|
||||
foreach ($c['Servers'] as $id => $server) {
|
||||
$ret .= '/* Server: ' . strtr($cf->getServerName($id), '*/', '-') . " [$id] */" . $crlf
|
||||
$ret .= '/* Server: ' . strtr($cf->getServerName($id) . " [$id] ", '*/', '-') . "*/" . $crlf
|
||||
. '$i++;' . $crlf;
|
||||
foreach ($server as $k => $v) {
|
||||
$k = preg_replace('/[^A-Za-z0-9_]/', '_', $k);
|
||||
|
Reference in New Issue
Block a user