Escape zero_rows (this is not dangerous, but I think it should be escaped).
This commit is contained in:
2
sql.php
2
sql.php
@@ -504,7 +504,7 @@ if (0 == $num_rows || $is_affected) {
|
|||||||
// the form should not have priority over
|
// the form should not have priority over
|
||||||
// errors like $strEmptyResultSet
|
// errors like $strEmptyResultSet
|
||||||
} elseif (!empty($zero_rows) && !$is_select) {
|
} elseif (!empty($zero_rows) && !$is_select) {
|
||||||
$message = PMA_Message::rawSuccess($zero_rows);
|
$message = PMA_Message::rawSuccess(htmlspecialchars($zero_rows));
|
||||||
} elseif (!empty($GLOBALS['show_as_php'])) {
|
} elseif (!empty($GLOBALS['show_as_php'])) {
|
||||||
$message = PMA_Message::success('strShowingPhp');
|
$message = PMA_Message::success('strShowingPhp');
|
||||||
} elseif (isset($GLOBALS['show_as_php'])) {
|
} elseif (isset($GLOBALS['show_as_php'])) {
|
||||||
|
Reference in New Issue
Block a user