Fix XSS on tablename and pred_tablename.
This commit is contained in:
@@ -1923,7 +1923,7 @@ if (empty($_REQUEST['adduser']) && (! isset($checkprivs) || ! strlen($checkprivs
|
|||||||
if (isset($tablename)) {
|
if (isset($tablename)) {
|
||||||
echo ' [ ' . $GLOBALS['strTable'] . ' <a href="'
|
echo ' [ ' . $GLOBALS['strTable'] . ' <a href="'
|
||||||
. $GLOBALS['cfg']['DefaultTabTable'] . '?' . $GLOBALS['url_query']
|
. $GLOBALS['cfg']['DefaultTabTable'] . '?' . $GLOBALS['url_query']
|
||||||
. '&db=' . $url_dbname . '&table=' . urlencode($tablename)
|
. '&db=' . $url_dbname . '&table=' . htmlspecialchars(urlencode($tablename))
|
||||||
. '&reload=1">' . htmlspecialchars($tablename) . ': '
|
. '&reload=1">' . htmlspecialchars($tablename) . ': '
|
||||||
. PMA_getTitleForTarget($GLOBALS['cfg']['DefaultTabTable'])
|
. PMA_getTitleForTarget($GLOBALS['cfg']['DefaultTabTable'])
|
||||||
. "</a> ]\n";
|
. "</a> ]\n";
|
||||||
|
Reference in New Issue
Block a user