Fix XSS on delimiter in tbl_sql.php.

This commit is contained in:
Michal Čihař
2010-08-17 16:23:09 +02:00
parent 4951fd1c85
commit 110c44a7a3

View File

@@ -37,7 +37,7 @@ require_once './libraries/tbl_links.inc.php';
/**
* Query box, bookmark, insert data from textfile
*/
PMA_sqlQueryForm(true, false, isset($_REQUEST['delimiter']) ? $_REQUEST['delimiter'] : ';');
PMA_sqlQueryForm(true, false, isset($_REQUEST['delimiter']) ? htmlspecialchars($_REQUEST['delimiter']) : ';');
/**
* Displays the footer