security fix
This commit is contained in:
@@ -5,6 +5,9 @@ phpMyAdmin - Changelog
|
|||||||
$Id$
|
$Id$
|
||||||
$Source$
|
$Source$
|
||||||
|
|
||||||
|
2004-02-02 Marc Delisle <lem9@users.sourceforge.net>
|
||||||
|
* export.php: security fix, thanks to Cedric Cochin for the advisory
|
||||||
|
|
||||||
2004-02-02 Alexander M. Turek <supposedformerinfatuationjunkie@derrabus.de>
|
2004-02-02 Alexander M. Turek <supposedformerinfatuationjunkie@derrabus.de>
|
||||||
* libraries/mysql_charsets.lib.php: Use PMA_backquote().
|
* libraries/mysql_charsets.lib.php: Use PMA_backquote().
|
||||||
|
|
||||||
|
@@ -21,7 +21,7 @@ if ($what == 'excel') {
|
|||||||
/**
|
/**
|
||||||
* Defines the url to return to in case of error in a sql statement
|
* Defines the url to return to in case of error in a sql statement
|
||||||
*/
|
*/
|
||||||
require('./libraries/export/' . $type . '.php');
|
require('./libraries/export/' . preg_replace('@\.\.*@','.',$type) . '.php');
|
||||||
|
|
||||||
// Generate error url
|
// Generate error url
|
||||||
if ($export_type == 'server') {
|
if ($export_type == 'server') {
|
||||||
|
Reference in New Issue
Block a user