[security] Global variables scope injection vulnerability (see PMASA-2013-7)

This commit is contained in:
Marc Delisle 2013-06-28 13:09:13 -04:00
parent 64c2b9a59c
commit 0124642684
2 changed files with 21 additions and 0 deletions

View File

@ -1,6 +1,9 @@
phpMyAdmin - ChangeLog
======================
4.0.4.1 ()
- [security] Global variables scope injection vulnerability (see PMASA-2013-7)
4.0.4.0 (2013-06-17)
- bug #3959 Using DefaultTabDatabase in NavigationTree for Database Click
- bug #3961 Avoid Suhosin warning when in simulation mode

View File

@ -122,6 +122,24 @@ if ($_POST == array() && $_GET == array()) {
* We only need to load the selected plugin
*/
if (! in_array(
$format,
array(
'csv',
'ldi',
'mediawiki',
'ods',
'shp',
'sql',
'xml'
)
)
) {
// this should not happen for a normal user
// but only during an attack
PMA_fatalError('Incorrect format parameter');
}
$post_patterns = array(
'/^force_file_/',
'/^'. $format . '_/'