Fix XSS on tablename and pred_tablename.
This commit is contained in:
@@ -1923,7 +1923,7 @@ if (empty($_REQUEST['adduser']) && (! isset($checkprivs) || ! strlen($checkprivs
|
||||
if (isset($tablename)) {
|
||||
echo ' [ ' . $GLOBALS['strTable'] . ' <a href="'
|
||||
. $GLOBALS['cfg']['DefaultTabTable'] . '?' . $GLOBALS['url_query']
|
||||
. '&db=' . $url_dbname . '&table=' . urlencode($tablename)
|
||||
. '&db=' . $url_dbname . '&table=' . htmlspecialchars(urlencode($tablename))
|
||||
. '&reload=1">' . htmlspecialchars($tablename) . ': '
|
||||
. PMA_getTitleForTarget($GLOBALS['cfg']['DefaultTabTable'])
|
||||
. "</a> ]\n";
|
||||
|
Reference in New Issue
Block a user