From 012464268420e53a9cd81cbb4a43988d70393c36 Mon Sep 17 00:00:00 2001 From: Marc Delisle Date: Fri, 28 Jun 2013 13:09:13 -0400 Subject: [PATCH] [security] Global variables scope injection vulnerability (see PMASA-2013-7) --- ChangeLog | 3 +++ import.php | 18 ++++++++++++++++++ 2 files changed, 21 insertions(+) diff --git a/ChangeLog b/ChangeLog index 8b29aabbd9..b1430c4908 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,6 +1,9 @@ phpMyAdmin - ChangeLog ====================== +4.0.4.1 () +- [security] Global variables scope injection vulnerability (see PMASA-2013-7) + 4.0.4.0 (2013-06-17) - bug #3959 Using DefaultTabDatabase in NavigationTree for Database Click - bug #3961 Avoid Suhosin warning when in simulation mode diff --git a/import.php b/import.php index 9d193ae63d..6075d5d94f 100644 --- a/import.php +++ b/import.php @@ -122,6 +122,24 @@ if ($_POST == array() && $_GET == array()) { * We only need to load the selected plugin */ +if (! in_array( + $format, + array( + 'csv', + 'ldi', + 'mediawiki', + 'ods', + 'shp', + 'sql', + 'xml' + ) +) +) { + // this should not happen for a normal user + // but only during an attack + PMA_fatalError('Incorrect format parameter'); +} + $post_patterns = array( '/^force_file_/', '/^'. $format . '_/'