Fix XSS on checkprivs.
This commit is contained in:
@@ -2150,7 +2150,7 @@ if (empty($_REQUEST['adduser']) && (! isset($checkprivs) || ! strlen($checkprivs
|
|||||||
|
|
||||||
// Offer to create a new user for the current database
|
// Offer to create a new user for the current database
|
||||||
echo '<fieldset id="fieldset_add_user">' . "\n"
|
echo '<fieldset id="fieldset_add_user">' . "\n"
|
||||||
. ' <a href="server_privileges.php?' . $GLOBALS['url_query'] . '&adduser=1&dbname=' . $checkprivs .'">' . "\n"
|
. ' <a href="server_privileges.php?' . $GLOBALS['url_query'] . '&adduser=1&dbname=' . htmlspecialchars($checkprivs) .'">' . "\n"
|
||||||
. PMA_getIcon('b_usradd.png')
|
. PMA_getIcon('b_usradd.png')
|
||||||
. ' ' . $GLOBALS['strAddUser'] . '</a>' . "\n"
|
. ' ' . $GLOBALS['strAddUser'] . '</a>' . "\n"
|
||||||
. '</fieldset>' . "\n";
|
. '</fieldset>' . "\n";
|
||||||
|
Reference in New Issue
Block a user