From 9385dde992dfa93080629f485ccf3a5c88a56aa5 Mon Sep 17 00:00:00 2001 From: Marc Delisle Date: Mon, 12 Nov 2007 17:55:31 +0000 Subject: [PATCH] bug #178988 [display] space before SHOW COLUMNS --- ChangeLog | 1 + sql.php | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index ee140a462..80d1f4226 100644 --- a/ChangeLog +++ b/ChangeLog @@ -34,6 +34,7 @@ $HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyA - bug #1823045 [import] Error importing file with lowercase "delimiter" - bug #1828913 [structure] Can't set FULLTEXT index on CHAR column - bug #1804081 [export] export on server doesn't obey AllowAnyWhereRecoding +- bug #178988 [display] space before SHOW COLUMNS 2.11.2.1 (2007-11-11) - fixed possible SQL injection using database name diff --git a/sql.php b/sql.php index 0eab30fc8..72fd3ecbb 100644 --- a/sql.php +++ b/sql.php @@ -245,7 +245,7 @@ if ($is_select) { // see line 141 } } elseif (preg_match('@^UPDATE[[:space:]]+@i', $sql_query)) { $is_affected = true; -} elseif (preg_match('@^SHOW[[:space:]]+@i', $sql_query)) { +} elseif (preg_match('@^[[:space:]]*SHOW[[:space:]]+@i', $sql_query)) { $is_show = true; } elseif (preg_match('@^(CHECK|ANALYZE|REPAIR|OPTIMIZE)[[:space:]]+TABLE[[:space:]]+@i', $sql_query)) { $is_maint = true;