diff --git a/server_privileges.php b/server_privileges.php index 9f052926e..1ed1539cb 100644 --- a/server_privileges.php +++ b/server_privileges.php @@ -1349,12 +1349,12 @@ $link_export = ''; - $grants = PMA_DBI_fetch_result("SHOW GRANTS FOR '" . $_REQUEST['username'] . "'@'" . $_REQUEST['hostname'] . "'"); + $grants = PMA_DBI_fetch_result("SHOW GRANTS FOR '" . PMA_sqlAddslashes($username) . "'@'" . PMA_sqlAddslashes($hostname) . "'"); foreach($grants as $one_grant) { echo $one_grant . "\n\n"; } echo ''; - unset($_REQUEST['username'], $_REQUEST['hostname'], $username, $hostname, $grants, $one_grant); + unset($username, $hostname, $grants, $one_grant); } if (empty($_REQUEST['adduser']) && (! isset($checkprivs) || ! strlen($checkprivs))) {