fixed possible SQL injection using database name
This commit is contained in:
@@ -1993,7 +1993,7 @@ if (empty($_REQUEST['adduser']) && (! isset($checkprivs) || ! strlen($checkprivs
|
||||
$sql_query =
|
||||
'(SELECT ' . $list_of_privileges . ', `Db`'
|
||||
.' FROM `mysql`.`db`'
|
||||
.' WHERE \'' . $checkprivs . "'"
|
||||
.' WHERE \'' . PMA_sqlAddslashes($checkprivs) . "'"
|
||||
.' LIKE `Db`'
|
||||
.' AND NOT (' . $list_of_compared_privileges. ')) '
|
||||
.'UNION '
|
||||
|
Reference in New Issue
Block a user