Commit Graph

9954 Commits

Author SHA1 Message Date
Michal Čihař
8b7f07cd95 Fix XSS on username. 2010-08-18 12:25:35 +02:00
Michal Čihař
1fe1aa6c0e Fix XSS on tablename and pred_tablename. 2010-08-18 12:23:13 +02:00
Michal Čihař
8b8ce64792 Fix XSS on dbname. 2010-08-18 12:22:19 +02:00
Michal Čihař
0fe30236fa Document PMA_sanitize. 2010-08-18 11:47:54 +02:00
Michal Čihař
a4a54da173 Escape html chars in form values. 2010-08-18 11:47:46 +02:00
Michal Čihař
c69fca50ee Add option to escape PMA_sanitize output.
This is required when it is used in form values.
2010-08-18 11:47:35 +02:00
Michal Čihař
c910f4c9ec Fix handling of unknown sort order. 2010-08-18 11:46:29 +02:00
Michal Čihař
08e27b8907 Secure handling of sort_by and sort_order in server_databases.php. 2010-08-18 11:46:29 +02:00
Michal Čihař
110c44a7a3 Fix XSS on delimiter in tbl_sql.php. 2010-08-18 11:46:29 +02:00
Marc Delisle
4951fd1c85 Fix XSS on delimiter in db_sql.php. 2010-08-18 11:46:29 +02:00
Michal Čihař
8ae41bbc02 Merge remote branch 'origin/MAINT_2_11_10' into QA_2_11
Conflicts:
	ChangeLog
	Documentation.html
	README
	libraries/Config.class.php
	translators.html
2010-03-11 13:51:07 +01:00
Herman van Rink
f175026ff0 [core] Fix broken cleanup of $_GET 2009-12-28 15:50:36 +00:00
Marc Delisle
8535d48ae9 2.11.10 release 2009-12-07 17:13:18 +00:00
Marc Delisle
13fc94b844 2.11.11-dev 2009-12-07 17:01:31 +00:00
Michal Čihař
719e0dce65 [setup] avoid usage of (un)serialize, what might be unsafe in some cases 2009-12-07 13:09:09 +00:00
Marc Delisle
628b38373b 2.11.9.6 release 2009-10-12 22:27:06 +00:00
Marc Delisle
212daad0c0 [security] XSS and SQL injection 2009-10-12 21:47:40 +00:00
Marc Delisle
deb1b31cae [security] XSS and SQL injection 2009-10-12 21:47:40 +00:00
Michal Čihař
72f86848c3 Document removal of config directory after configuring phpMyAdmin. 2009-03-25 08:30:28 +00:00
Michal Čihař
a6a45d7138 Document removal of config directory after configuring phpMyAdmin. 2009-03-25 08:30:28 +00:00
Marc Delisle
7b5ec357bc 2.11.9.5 2009-03-24 21:04:18 +00:00
Marc Delisle
8e18c2d8df 2.11.9.5 2009-03-24 21:04:18 +00:00
Michal Čihař
aeae6df369 Use official names for wiki (wiki.phpmyadmin.net) and demo server (demo.phpmyadmin.net). 2009-03-24 12:56:58 +00:00
Michal Čihař
649d13e234 Use official names for wiki (wiki.phpmyadmin.net) and demo server (demo.phpmyadmin.net). 2009-03-24 12:56:58 +00:00
Michal Čihař
36ddf8b61e Escape special chars when displaying filename template cookies. 2009-03-24 08:55:07 +00:00
Michal Čihař
c05d94cdd9 Escape special chars when displaying filename template cookies. 2009-03-24 08:55:07 +00:00
Michal Čihař
460a649dbc Do not output unescaped chars to generated configuration file. 2009-03-24 08:34:23 +00:00
Michal Čihař
e70d7b4332 Do not output unescaped chars to generated configuration file. 2009-03-24 08:34:23 +00:00
Marc Delisle
18d7934405 2.11.9.4 2008-12-09 17:03:54 +00:00
Michal Čihař
2748fc9fac Forgotten branch. 2008-12-09 14:03:57 +00:00
Michal Čihař
0d4adbfc19 [security] possible XSRF on several pages 2008-12-09 13:45:32 +00:00
Michal Čihař
5b781c4a72 Adjust create-release.sh instructions to match current website. 2008-11-21 08:58:00 +00:00
Michal Čihař
ebba6d7863 Adjust create-release.sh instructions to match current website. 2008-11-21 08:58:00 +00:00
Michal Čihař
fb0bb67f49 Adjust create-release.sh instructions to match current website. 2008-11-21 08:58:00 +00:00
Michal Čihař
1639051ec7 Adjust create-release.sh instructions to match current website. 2008-11-21 08:58:00 +00:00
Marc Delisle
a2a8959eb4 bug #2222230 [import] Assigning a value in import.php 2008-11-04 20:52:08 +00:00
Marc Delisle
61f2983838 added a define() to enable running of test/AllTests.php, thanks to Sebastian Mendel 2008-10-30 21:22:00 +00:00
Marc Delisle
bfda20f58e added a define() to enable running of test/AllTests.php, thanks to Sebastian Mendel 2008-10-30 21:22:00 +00:00
Marc Delisle
bcd216e529 2.11.9.3 2008-10-30 20:40:33 +00:00
Marc Delisle
712451fa1f 3.0.1.1 2008-10-30 20:22:20 +00:00
Marc Delisle
625e9f2e93 [security] XSS in a Designer component 2008-10-30 12:47:24 +00:00
Marc Delisle
3d83805ab4 [security] XSS in a Designer component 2008-10-30 12:47:24 +00:00
Marc Delisle
f1a0d3d2da [security] XSS in a Designer component 2008-10-30 12:47:24 +00:00
Marc Delisle
ea4eb8eea0 [security] XSS in a Designer component 2008-10-30 12:47:24 +00:00
Marc Delisle
d848ff485b unit testing: missing required library 2008-10-29 20:44:14 +00:00
Marc Delisle
a47f935012 unit testing: missing required library 2008-10-29 20:44:14 +00:00
Marc Delisle
f5564c9ca3 update FAQ for new translators 2008-10-27 15:19:03 +00:00
Marc Delisle
c62b363942 bug #2107583 [GUI] Leading newline truncated, thanks to Isart Montane 2008-10-25 14:40:48 +00:00
Marc Delisle
8c697864eb fix vim modelines 2008-10-25 13:37:54 +00:00
Marc Delisle
0cd015b6d3 Italian update (#2187811) 2008-10-25 04:12:23 +00:00