diff --git a/ChangeLog b/ChangeLog index 004b9cf5b1..4e2fb84740 100644 --- a/ChangeLog +++ b/ChangeLog @@ -41,6 +41,7 @@ phpMyAdmin - ChangeLog - issue #12799 Allow to configure signon session parameters - issue #12854 Drop database is broken - issue #12863 Can't toggle Event Scheduler on +- issue #12742 Finish removing dead code references to xls/xlsx import and export, which was removed some time ago. - issue #12536 Rename "Relations" to "Relationships" in many places as it's the more proper term 4.6.6 (not yet released) @@ -72,412 +73,9 @@ phpMyAdmin - ChangeLog - issue #12859 Changed WHERE condition to 0 instead of 1 for SQL query window to avoid accidents - issue #12872 Use same query for display and execution when dropping index - issue #12868 Fix check for user groups freatures being enabled +- issue #12831 Fix table formatting on Insert tab, which mostly affected row highlighting +- issue #12495 Reintroduced phpinfo page with limited capabilities -4.6.5.2 (2016-12-05) -- issue #12765 Fixed SQL export with newlines - -4.6.5.1 (2016-11-25) -- issue #12735 Incorrect parameters to escapeString in Node.php -- issue #12734 Fix PHP error when mbstring is not installed -- issue #12736 Don't force partition count to be specified when creating a new table - -4.6.5 (2016-11-24) -- issue Remove potentionally license problematic sRGB profile -- issue #12459 Display read only fields as read only when editing -- issue #12384 Fix expanding of navigation pane when clicking on database -- issue #12430 Impove partitioning support -- issue #12374 Reintroduced simplified PmaAbsoluteUri configuration directive -- issue Always use UTC time in HTTP headers -- issue #12479 Simplified validation of external links -- issue #12483 Fix browsing tables with built in transformations -- issue #12485 Do not show warning about short blowfish_secret if none is set -- issue #12251 Fixed random logouts due to wrong cookie path -- issue #12480 Fixed editing of ENUM/SET/DECIMAL fields structure -- issue #12497 Missing escaping of configuration used in SQL (hide_db and only_db) -- issue #12476 Add error checking in reading advisory rules file -- issue #12477 Add checking missing elements and confirming element types from json_decode -- issue #12251 Automatically save SQL query in browser local storage rather than in cookie -- issue #12292 Unable to edit transformations -- issue #12502 Remove unused paramenter when connecting to MySQLi -- issue #12303 Fix number formatting with different settings of precision in PHP -- issue #12405 Use single quotes in PHP code -- issue #12534 Option for the dropped column is not removed from 'after_field' select, after the column is dropped -- issue #12531 Properly detect DROP DATABASE queries -- issue #12470 Fix possible race condition in setting URL hash -- issue #11924 Remove caching of server information -- issue #11628 Proper parsing of INSERT ... ON DUPLICATE KEY queries -- issue #12545 Proper parsing of CREATE TABLE ... PARTITION queries -- issue #12473 Code can throw unhandled exception -- issue #12550 Do not try to keep alive session even after expiry -- issue #12512 Fixed rendering BBCode links in setup -- issue #12518 Fixed copy of table with generated columns -- issue #12221 Fixed export of table with generated columns -- issue #12320 Copying a user does not copy usergroup -- issue #12272 Adding a new row with default enum goes to no selection when you want to add more then 2 rows -- issue #12487 Drag and drop import prevents file dropping to blob column file selector on the insert tab -- issue #12554 Absence of scrolling makes it impossible to read longer text values in grid editing -- issue #12530 "Edit routine" crashes when the current user is not the definer, even if privileges are adequate -- issue #12300 Export selective tables by-default dumps Events also -- issue #12298 Fixed export of view definitions -- issue #12242 Edit routine detail dialog does not fill "Return length" field in mysql functions -- issue #12575 New index Confirm adds whitespace around the field name -- issue #12382 Bug in zoom search -- issue #12321 Assign LIMIT clause only to syntactically correct queries -- issue #12461 Can't Execute SQL With Sub-Query Due To "LIMIT 0,25" Inserted At Wrong Place -- issue #12511 Clarify documentation on ArbitraryServerRegexp -- issue #12508 Remove duplicate code in SQL escaping -- issue #12475 Cleanup code for getting table information -- issue #12579 phpMyAdmin's export of a Select statment without a FROM clause generates Wrong SQL -- issue #12316 Correct export of complex SELECT statements -- issue #12080 Fixed parsing of subselect queries -- issue #11740 Fixed handling DELETE ... USING queries -- issue #12100 Fixed handling of CASE operator -- issue #12455 Query history stores separate entry for every letter typed -- issue #12327 Create PHP code no longer works -- issue #12179 Fixed bookmarking of query with multiple statements -- issue #12419 Wrong description on GRANT OPTION -- issue #12615 Fixed regexp for matching browser versions -- issue #12569 Avoid showing import errors twice -- issue #12362 prefs_manage.php can leave an orphaned temporary file -- issue #12619 Unable to export csv when using union select -- issue #12625 Broken Edit links in query results of JOIN query -- issue #12634 Drop DB error in import if DB doesn't exist -- issue #12338 Designer reverts to first saved ER after EACH relation create or delete -- issue #12639 'Show trace' in Console generates JS error for functions in query's trace called without any arguments -- issue #12366 Fix user creation with certain MariaDB setups -- issue #12616 Refuse to work with mbstring.func_overload enabled -- issue #12472 Properly report connection without password in setup -- issue #12365 Fix records count for large tables -- issue #12533 Fix records count for complex queries -- issue #12454 Query history not updated in console until page refresh -- issue #12344 Fixed parsing of labels in loop -- issue #12228 Fixed parsing of BEGIN labels -- issue #12637 Fixed editing some timestamp values -- issue #12622 Fixed javascript error in designer -- issue #12334 Missing page indicator or VIEWs -- issue #12610 Export of tables with Timestamp/Datetime/Time columns defined with ON UPDATE clause with precision fails -- issue #12661 Error inserting into pma__history after timeout -- issue #12195 Row_format = fixed not visible -- issue #12665 Cannot add a foreign key - non-indexed fields not listed in InnoDB tables -- issue #12674 Allow for proper MySQL-allowed strings as identifiers -- issue #12651 Allow for partial dates on table insert page -- issue #12681 Fixed designer with tables using special chars -- issue #12652 Fixed visual query builder for foreign keys with more fields -- issue #12257 Improved search page performance -- issue #12322 Avoid selecting default function for foreign keys -- issue #12453 Fixed escaping of SQL parts in some corner cases -- issue #12542 Missing table name in account privileges editor -- issue #12691 Remove ksort call on empty array in PMA_getPlugins function -- issue #12443 Check parameter type before processing -- issue #12299 Avoid generating too long URLs in search -- issue #12361 Fix self SQL injection in table-specific privileges -- issue #12698 Add link to release notes and download on new version notification -- issue #12712 Error when trying to setup replication (fatal error in call to an old PMA_DBI_connect function) -- issue [security] Unsafe generation of $cfg['blowfish_secret'], see PMASA-2016-58 -- issue [security] phpMyAdmin's phpinfo functionality is removed, see PMASA-2016-59 -- issue [security] AllowRoot and allow/deny rule bypass with specially-crafted username, see PMASA-2016-60 -- issue [security] Username matching weaknesses with allow/deny rules, see PMASA-2016-61 -- issue [security] Possible to bypass logout timeout, see PMASA-2016-62 -- issue [security] Full path disclosure (FPD) weaknesses, see PMASA-2016-63 -- issue [security] Multiple XSS weaknesses, see PMASA-2016-64 -- issue [security] Multiple denial-of-service (DOS) vulnerabilities, see PMASA-2016-65 -- issue [security] Possible to bypass white-list protection for URL redirection, see PMASA-2016-66 -- issue [security] BBCode injection to login page, see PMASA-2016-67 -- issue [security] Denial-of-service (DOS) vulnerability in table partitioning, see PMASA-2016-68 -- issue [security] Multiple SQL injection vulnerabilities, see PMASA-2016-69 -- issue [security] Incorrect serialized string parsing, see PMASA-2016-70 -- issue [security] CSRF token not stripped from the URL, see PMASA-2016-71 - -4.6.4 (2016-08-16) -- issue [security] Weaknesses with cookie encryption, see PMASA-2016-29 -- issue [security] Improve session cookie code for openid.php and signon.php example files -- issue [security] Full path disclosure in openid.php and signon.php example files -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-30 -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-31 -- issue [security] Unsafe generation of BlowfishSecret (when not supplied by the user) -- issue [security] Referrer leak when phpinfo is enabled -- issue [security] PHP code injection, see PMASA-2016-32 -- issue [security] Full path disclosure, see PMASA-2016-33 -- issue [security] SQL injection attack, see PMASA-2016-34 -- issue [security] Local file exposure through LOAD DATA LOCAL INFILE, see PMASA-2016-35 -- issue [security] Local file exposure through symlinks with UploadDir, see PMASA-2016-36 -- issue [security] Path traversal with SaveDir and UploadDir, see PMASA-2016-37 -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-38 -- issue [security] SQL injection vulnerability as control user, see PMASA-2016-39 -- issue [security] SQL injection vulnerability, see PMASA-2016-40 -- issue [security] Denial-of-service attack through transformation feature, see PMASA-2016-41 -- issue [security] SQL injection vulnerability as control user, see PMASA-2016-42 -- issue [security] Verify data before unserializing, see PMASA-2016-43 -- issue [security] Use HTTPS for wiki links -- issue Remove Swekey support -- issue [security] Denial-of-service attack with $cfg['AllowArbitraryServer'] = true and persistent connections, see PMASA-2016-45 -- issue [security] Improve SSL certificate handling -- issue [security] Fix full path disclosure in debugging code -- issue [security] Possible circumvention of IP-based allow/deny rules with IPv6 and proxy server, see PMASA-2016-47 -- issue [security] Detect if user is logged in, see PMASA-2016-48 -- issue [security] Bypass URL redirection protection, see PMASA-2016-49 -- issue [security] Referrer leak, see PMASA-2016-50 -- issue [security] Reflected File Download, see PMASA-2016-51 -- issue [security] ArbitraryServerRegexp bypass, see PMASA-2016-52 -- issue [security] Denial-of-service attack by entering long password, see PMASA-2016-53 -- issue [security] Remote code execution vulnerability when running as CGI, see PMASA-2016-054 -- issue [security] Administrators could trigger SQL injection attack against users -- issue [security] Denial-of-service attack when PHP uses dbase extension, see PMASA-2016-55 -- issue [security] Remove tode execution vulnerability when PHP uses dbase extension, see PMASA-2016-56 -- issue [security] Denial-of-service attack by using for loops, see PMASA-2016-46 -- issue Include X-Robots-Tag header in responses -- issue Enforce numeric field length when creating table -- issue Fixed invalid Content-Length in some HTTP responses -- issue #12394 Create view should require a view name -- issue #12391 Message with 'Change password successfully' displayed, but does not take effect -- issue Tighten control on PHP sessions and session cookies -- issue #12409 Re-enable overhead on server databases view -- issue #12414 Fixed rendering of Original theme -- issue #12413 Fixed deleting users in non English locales -- issue #12416 Fixed replication status output in Databases listing -- issue #12303 Avoid typecasting to float when not needed -- issue #12425 Duplicate message variable names in messages.inc.php -- issue #12399 Adding index to table shows wrong top navigation -- issue #12424 Fixed password change on MariaDB without auth plugin -- issue #12339 Do not error on unset server port -- issue #12422 Improvements to the original theme -- issue #12395 Do not try to load old transformation plugins -- issue #12423 Fixed replication status in database listing -- issue #12433 Copy table with prefix does not copy the indexes -- issue #12375 Search in database: Window content is not scrolling down when clicking first time on Browse link -- issue #12346 SQL Editor textareas can have their size increased from the top, distorting the page view - -4.6.3 (2016-06-23) -- issue #12249 Fixed cookie path on Windows -- issue #12279 Fixed error reporting on connect problems -- issue #12290 Fixed export of tables without explicitly set engine -- issue #12285 Designer JavaScript error: Show/Hide tables list -- issue #12293 Fix MySQL SSL connection with some PHP versions -- issue #12279 Fix MySQL connection error on version mismatch -- issue #12281 Keep user attributes (privileges, authentication mode, etc) when copying a user -- issue #12308 Fix division by zero in case of misconfigured MySQL server -- issue #12317 Fix editing server variables -- issue #12303 Fix table size calculation in some circumstances -- issue #12310 Fix listing routines for non privileged user -- issue Escape generated query in exporting a database -- issue Setup script doesn't use input type 'password' in all relevant locations -- issue [security] BBCode injection in setup script, see PMASA-2016-17 -- issue [security] Cookie attribute injection attack, see PMASA-2016-18 -- issue Redirect loop when directly calling url.php -- issue [security] SQL injection attack, see PMASA-2016-19 -- issue [security] XSS attack in Table Structure page, see PMASA-2016-20 -- issue [security] XSS attack in Server Privileges page, see PMASA-2016-21 -- issue [security] DOS attack vulnerability, see PMASA-2016-22 -- issue [security] Multiple full path disclosure vulnerabilities, see PMASA-2016-23 -- issue [security] Full path disclosure when running in debug mode -- issue [security] XSS attack with partition range and table structure, see PMASA-2016-25 -- issue [security] XSS attack when checking database privileges, see PMASA-2016-26 -- issue [security] XSS attack when MySQL server is using a specific payload log_bin directive, see PMASA-2016-26 -- issue [security] XSS vulnerabilities in Transformation feature, see PMASA-2016-26 - -4.6.2 (2016-05-25) -- issue [security] User SQL queries can be revealed through URL GET parameters, see PMASA-2016-14 -- issue [security] Self XSS vulneratbility, see PMASA-2016-16 -- issue #12225 Use https for documentation links -- issue #12234 Fix schema export with too many tables -- issue #12240 Avoid parsing non JSON responses as JSON -- issue #12244 Avoid using too log URLs when getting javascripts -- issue #12118 Fixed setting mixed case languages -- issue #12229 Avoid storing objects in session when debugging SQL -- issue #12249 Fix cookie path on IIS -- issue #11705 Fix occassional 200 errors on Windows -- issue #12219 Fix locking issues when importing SQL -- issue #12231 Avoid confusing warning when mysql extension is missing -- issue Improve handling of logout -- issue Safer handling of sessions during authentication -- issue #12209 Fix server selection on main page -- issue #12192 Avoid storing full error data in session -- issue #12082 Fixed export of ARCHIVE tables with keys -- issue #11565 Add session reload for config authentication -- issue #12229 Do not fail on errors stored in session -- issue #12248 Fix loading of APC based upload progress bar - -4.6.1 (2016-05-02) -- issue #12120 PMA_Util not found in insert_edit.lib.php -- issue #12118 Fixed activation of some languages -- issue #12121 Fixed error in 3NF step of normalization -- issue #12135 Fix offering JSON datatype in incompatible MySQL versions -- issue #12132 Can not open table with JSON field -- issue #12125 Cannot highlight a column if I scroll down from the top of the table -- issue #12154 Fixed possible PHP error in SQL parser -- issue #12029 Fixed SQL quoting in SQL export -- issue #12129 Improve performance of database structure page -- issue #12159 Fix PHP error if user did unpack new version over old one -- issue #12165 Fix parsing of expression 0 -- issue #12146 Document setup with Google Cloud SQL -- issue #12197 Fix parsing of queries with double \ -- issue #12202 Fixed setting of language from user configuration -- issue #12200 Fixed check for ndb version -- issue #12206 Fixed loading of configuration file -- issue #12204 Check if sessions are working and report failures -- issue #12211 non-clickable initial letter for users / and can't modify users with MySQL 5.7.12 -- issue #12215 Fixed config tab persistence errors -- issue #12217 Fixed javascript erros on user creation -- issue #12144 Fixed parsing of some AS clauses -- issue #12205 Fixed parsing of FULL OUTER JOIN queries -- issue #12171 Fixed editing of VIEW structure -- issue #12208 Avoid printing executed queries on import - -4.6.0.0 (2016-03-22) -+ issue #11456 Disabled storage engines -+ issue #11479 Allow setting routine wise privileges -- issue Hide Insert tab for non-updatable views -+ issue #11490 UI for defining partitioning in create table window -+ issue #11438 Support JSON data type -+ issue Editing partitions in table Structure -- issue Tracking does not make sense for information_schema -- issue #11550 Regression in Find and replace -+ issue #11619 TokuDB Tables Show Size as "unknown" -+ issue #11654 Use a slider for Internal relations -+ issue #11641 Ability to disable the navigationhiding Feature -- issue #11647 Restrict configuration NavigationTreeDbSeparator to strings -- issue #11667 Disable the tooltip in the navigation panel's filter box -+ issue Copy results to clipboard -+ issue #11504 Reactivate cut&paste possibility in print view -- issue #11702 Extraneous message after edit + grid-edit -- issue #11668 Table header is empty with browsing an empty table -+ issue #11701 Allow changing parameter order of routines -- issue #11708 Remove no password warning -+ issue #11711 Clarify the meaning of "Stand-in structure for view" in SQL export -- issue HTML line break shown after a MySQL connection error message -- issue #11728 CSV import skip row count after -- issue Fixed displaying of SQL query on table operations -- issue #6321 Display binary strings as text if they are valid UTF-8 -+ issue #11743 Display routine specific privileges -+ issue #11538 Copy multiple tables to database -+ issue Support Cloudflare Flexible SSL -- issue Handle empty TABLE_COMMENT -+ issue #11833 Drop support for old Internet Explorer versions -+ issue #11796 Use modals for displaying forms in db structure page -+ issue #11789 Show MySQL error messages in user language -+ issue Add 'ssl_verify' configuration directive for self-signed certificates with mysqlnd and PHP >= 5.6 -+ issue #11874 Show more used PHP extensions -- issue #11874 Report when version check and error reporting are disabled -- issue #11849 Fix PDF schema export -- issue #11412 Remove ForceSSL configuration directive -- issue Remove support for Mozilla Prism -- issue #11412 Remove PmaAbsoluteUri configuration directive -- issue #11914 Fix autoloading of phpseclib -- issue #11880 Fixed rendering of missing extension error -- issue #11923 Errors on Structure tab when user only has select access on certain columns -- issue #11972 Missing documentation for $cfg['Servers'][$i]['favorite'] and $cfg['NumFavoriteTables'] -- issue #11907 Avoid displaying UPDATE query twice -- issue #11850 Fixed CSV import -- issue Fix SQL syntax highlighting in database search page -- issue #12056 Fix error when we can not generate random string -- issue #12055 Fixed PHP syntax error in templates -- issue #12054 Fixed processing of queries with escaped quotes -- issue #12041 Fixed exporting tables with fields DEFAULT and COMMENT -- issue #12073 Hide edit and delete buttons when the results are not related to a table -- issue #12083 Fixed parsing of field definition -- issue #12081 Fixed rendering of table stats -- issue #11705 Fixed problems with PHP on Windows on table structure -- issue #12085 Like search strings being escaped incorrectly -- issue #12092 Rename exported databases/tables doesn't seem to work -- issue #12099 Undefined index: controllink -- issue #12094 PHP Fatal error: Call to undefined function __() -- issue #12098 Fix login after logout with http authentication -- issue #12074 Fixed possible invalid SQL export -- issue #12026 Fixed parsing of UNION SELECT with brackets -- issue #12109 Fixed parsing of CREATE TABLE [AS] SELECT -- issue #12105 Multi-server drap-and-drop import always fails -- issue #12116 Fulltext indexes are not copied when using copy database function - -4.5.5.1 (2016-02-29) -- issue #11971 CREATE UNIQUE INDEX index type is not recognized by parser. -- issue #11982 Row count wrong when grouping joined tables. -- issue #12012 Column definition with default value and comment in CREATE TABLE expoerted faulty. -- issue #12020 New statement but no delimiter and unexpected token with REPLACE. -- issue #12029 Fixed incorrect usage of SQL parser context in SQL export -- issue [security] XSS vulnerability in SQL parser, see PMASA-2016-10. -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-11. -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-12. -- issue [security] Vulnerability allowing man-in-the-middle attack on API call to GitHub, see PMASA-2016-13. -- issue #12048 Fixed inclusion of gettext library from SQL parser - -4.5.5.0 (2016-02-22) -- issue Undefined index: is_ajax_request -- issue #11855 Fix password change on MariaDB 10.1 and newer -- issue #11874 Validate version information before further processing it -- issue #11881 Full processlist lost on refresh -- issue #11834 Adjust privileges fails if database name contains underscores -- issue #11906 'Loading...' banner shows on login screen -- issue #11930 Fixed changing of table parameters, eg. AUTO_INCREMENT -- issue #11885 Call to undefined function SqlParser\ctype_alnum() -- issue #11879 4.5.3.1 - NOW() function not recognized by parser -- issue #11867 Gracefully handle the DESC statement -- issue #11843 Fractional timestamp causes corrupted SQL export -- issue #11836 Static analysis error for valid WHERE condition with IF keyword -- issue #11800 Syntax Verifier error using REGEXP in SQL statement -- issue #11799 Backslashes in comments are being interpreted as escape characters -- issue #11909 Can't insert row into table that contains generated column -- issue #11677 sql-parser and php-gettext collide. -- issue #11920 Can't disable backquotes in export -- issue #11911 Inserts via tbl_change.php in VARBINARY columns does not allow using HEX() and MD5() -- issue #11939 Correct content type for uploaded error reports -- issue #11940 Silent errors from checking local documentation -- issue #11944 Fixed error on servers with disabled php_uname -- issue #11946 Correctly store and report file upload errors -- issue #11948 Avoid javascript errors on invalid location hash -- issue #11950 Fix PHP warning on configuration errors -- issue #11951 Silent errors on checking for writable folders -- issue #11952 Silent warning on invalid file upload -- issue #11953 Do not fail getting filename with open_basedir limitations -- issue #11956 unrecognized keyword interval -- issue Field names and aliases are being correctly parsed now. -- issue #11959 Fix javascript error in setup -- issue #11964 Undefined index: TABLE_COMMENT in database structure page -- issue #11967 Fix PHP error on loading invalid XML or ODS file -- issue #11969 Missing confirmation while dropping a view in view_operations.php -- issue #11968 Fix export of index comments in SQL -- issue #11979 DECLARE not accepted as valid SQL - -4.5.4.1 (2016-01-29) -- issue #11892 Error with PMA 4.4.15.3 -- issue #11896 Remove hard dependency on phpseclib - -4.5.4.0 (2016-01-28) -- issue #11724 live data edit of big sets is not working -- issue Table list not saved in db QBE bookmarked search -- issue #11777 While 'changing a column', query fails with a syntax error after the 'CHARSET=' keyword -- issue #11783 Avoid syntax error in javascript messages on invalid PHP setting for max_input_vars -- issue #11784 Properly handle errors in upacking zip archive -- issue #11785 Set PHP's internal encoding to UTF-8 -- issue #11786 Fixed Kanji encoding in some specific cases -- issue #11787 Check whether iconv works before using it -- issue #11788 Avoid conversion of MySQL error messages -- issue #11792 Undefined index: parameters -- issue #11802 Undefined index: field_name_orig -- issue Undefined index: host -- issue #11810 'Add to central columns' (per column button) does nothing -- issue #11727 SQL duplicate entry error trying to INSERT in designer_settings table -- issue #11798 Fix handling of databases with dot in a name -- issue #11820 Fix hiding of page content behind menu -- issue #11780 FROM clause not generated after loading search bookmark -- issue #11826 Fix creating/editing VIEW with DEFINER containing special chars -- issue #11828 Do not invoke FLUSH PRIVILEGES when server in --skip-grant-tables -- issue #11804 Misleading message for configuration storage -- issue #11772 Table pagination does nothing when session expired -- issue #11840 Index comments not working properly -- issue #11791 Better handle local storage errors -- issue #11752 Improve detection of privileges for privilege adjusting -- issue #11854 Undefined property: stdClass::$releases at version check when disabled in config -- issue #11814 SQL comment and variable stripped from bookmark on save -- issue Gracefully handle errors in regex based javascript search -- issue [security] Multiple full path disclosure vulnerabilities, see PMASA-2016-1 -- issue [security] Unsafe generation of CSRF token, see PMASA-2016-2 -- issue [security] Multiple XSS vulnerabilities, see PMASA-2016-3 -- issue [security] Insecure password generation in JavaScript, see PMASA-2016-4 -- issue [security] Unsafe comparison of CSRF token, see PMASA-2016-5 -- issue [security] Multiple full path disclosure vulnerabilities, see PMASA-2016-6 -- issue [security] XSS vulnerability in normalization page, see PMASA-2016-7 -- issue [security] Full path disclosure vulnerability in SQL parser, see PMASA-2016-8 -- issue [security] XSS vulnerability in SQL editor, see PMASA-2016-9 --- Older ChangeLogs can be found on our project website --- https://www.phpmyadmin.net/old-stuff/ChangeLogs/ diff --git a/doc/config.rst b/doc/config.rst index 23904475d6..36b727a289 100644 --- a/doc/config.rst +++ b/doc/config.rst @@ -2038,6 +2038,11 @@ Main panel You can additionally hide more information by using :config:option:`$cfg['Servers'][$i]['verbose']`. +.. config:option:: $cfg['ShowPhpInfo'] + + :type: boolean + :default: false + .. config:option:: $cfg['ShowChgPassword'] :type: boolean @@ -2048,11 +2053,26 @@ Main panel :type: boolean :default: true - Defines whether to display the + Defines whether to display the :guilabel:`PHP information` and :guilabel:`Change password` links and form for creating database or not at the starting main (right) frame. This setting does not check MySQL commands entered directly. + Please note that to block the usage of ``phpinfo()`` in scripts, you have to + put this in your :file:`php.ini`: + + .. code-block:: ini + + disable_functions = phpinfo() + + .. warning:: + + Enabling phpinfo page will leak quite a lot of information about server + setup. Is it not recommended to enable this on shared installations. + + This might also make easier some remote attacks on your installations, + so enable this only when needed. + Also note that enabling the :guilabel:`Change password` link has no effect with config authentication mode: because of the hard coded password value in the configuration file, end users can't be allowed to change their diff --git a/export.php b/export.php index 091d41ad96..d1317ff565 100644 --- a/export.php +++ b/export.php @@ -186,9 +186,6 @@ $export_plugin = PMA_getPlugin( ) ); -// Backward compatibility -$type = $what; - // Check export type if (empty($export_plugin)) { PMA_fatalError(__('Bad type!')); @@ -318,13 +315,12 @@ if ($what == 'sql') { $crlf = PMA\libraries\Util::whichCrlf(); } -$output_kanji_conversion = Encoding::canConvertKanji() && $type != 'xls'; +$output_kanji_conversion = Encoding::canConvertKanji(); // Do we need to convert charset? $output_charset_conversion = $asfile && Encoding::isSupported() - && isset($charset) && $charset != 'utf-8' - && $type != 'xls'; + && isset($charset) && $charset != 'utf-8'; // Use on the fly compression? $GLOBALS['onfly_compression'] = $GLOBALS['cfg']['CompressOnFly'] diff --git a/index.php b/index.php index 2d9bb25e38..0ced453dd7 100644 --- a/index.php +++ b/index.php @@ -323,7 +323,7 @@ if ($server > 0 && $GLOBALS['cfg']['ShowServerInfo']) { . ' '; } -if ($GLOBALS['cfg']['ShowServerInfo']) { +if ($GLOBALS['cfg']['ShowServerInfo'] || $GLOBALS['cfg']['ShowPhpInfo']) { echo '
'; echo '

' , __('Web server') , '

'; echo ''; echo '
'; } diff --git a/js/server_status_queries.js b/js/server_status_queries.js index a5d75ea45f..99ac4bbf40 100644 --- a/js/server_status_queries.js +++ b/js/server_status_queries.js @@ -16,7 +16,7 @@ AJAX.registerOnload('server_status_queries.js', function () { // Build query statistics chart var cdata = []; try { - $.each(JSON.parse($('#serverstatusquerieschart_data').text()), function (key, value) { + $.each(JSON.parse($('#serverstatusquerieschart').data('chart'))), function (key, value) { cdata.push([key, parseInt(value, 10)]); }); $('#serverstatusquerieschart').data( diff --git a/js/tbl_zoom_plot_jqplot.js b/js/tbl_zoom_plot_jqplot.js index 35fdab8934..a99bf6cefe 100644 --- a/js/tbl_zoom_plot_jqplot.js +++ b/js/tbl_zoom_plot_jqplot.js @@ -96,19 +96,6 @@ function getType(field) { return 'text'; } } -/** - ** Converts a categorical array into numeric array - ** @param array categorical values array - **/ -function getCord(arr) { - var newCord = []; - var original = $.extend(true, [], arr); - arr = jQuery.unique(arr).sort(); - $.each(original, function (index, value) { - newCord.push(jQuery.inArray(value, arr)); - }); - return [newCord, arr, original]; -} /** ** Scrolls the view to the display section diff --git a/libraries/common.inc.php b/libraries/common.inc.php index 60ae8fa7f0..53eb937f6a 100644 --- a/libraries/common.inc.php +++ b/libraries/common.inc.php @@ -262,9 +262,6 @@ $GLOBALS['url_params'] = array(); * @global array $goto_whitelist */ $goto_whitelist = array( - //'browse_foreigners.php', - //'changelog.php', - //'chk_rel.php', 'db_datadict.php', 'db_sql.php', 'db_events.php', @@ -278,9 +275,6 @@ $goto_whitelist = array( 'db_routines.php', 'export.php', 'import.php', - //'index.php', - //'navigation.php', - //'license.php', 'index.php', 'pdf_pages.php', 'pdf_schema.php', @@ -313,7 +307,6 @@ $goto_whitelist = array( 'tbl_row_action.php', 'tbl_select.php', 'tbl_zoom_select.php', - //'themes.php', 'transformation_overview.php', 'transformation_wrapper.php', 'user_password.php', diff --git a/libraries/config.default.php b/libraries/config.default.php index c4b17993e9..a6fcca38cd 100644 --- a/libraries/config.default.php +++ b/libraries/config.default.php @@ -1058,6 +1058,13 @@ $cfg['NavigationTreeShowEvents'] = true; */ $cfg['ShowStats'] = true; +/** + * show PHP info link + * + * @global boolean $cfg['ShowPhpInfo'] + */ +$cfg['ShowPhpInfo'] = false; + /** * show MySQL server and web server information * @@ -1393,7 +1400,7 @@ $cfg['RowActionType'] = 'both'; $cfg['Export'] = array(); /** - * codegen/csv/excel/htmlexcel/htmlword/latex/ods/odt/pdf/sql/texytext/xls/xml/yaml + * codegen/csv/excel/htmlexcel/htmlword/latex/ods/odt/pdf/sql/texytext/xml/yaml * * @global string $cfg['Export']['format'] */ @@ -1609,48 +1616,6 @@ $cfg['Export']['texytext_columns'] = false; */ $cfg['Export']['texytext_null'] = 'NULL'; -/** - * - * - * @global boolean $cfg['Export']['xls_columns'] - */ -$cfg['Export']['xls_columns'] = false; - -/** - * - * - * @global string $cfg['Export']['xls_structure_or_data'] - */ -$cfg['Export']['xls_structure_or_data'] = 'data'; - -/** - * - * - * @global string $cfg['Export']['xls_null'] - */ -$cfg['Export']['xls_null'] = 'NULL'; - -/** - * - * - * @global boolean $cfg['Export']['xlsx_columns'] - */ -$cfg['Export']['xlsx_columns'] = false; - -/** - * - * - * @global string $cfg['Export']['xlsx_structure_or_data'] - */ -$cfg['Export']['xlsx_structure_or_data'] = 'data'; - -/** - * - * - * @global string $cfg['Export']['xlsx_null'] - */ -$cfg['Export']['xlsx_null'] = 'NULL'; - /** * * @@ -2366,27 +2331,6 @@ $cfg['Import']['ods_recognize_percentages'] = true; */ $cfg['Import']['ods_recognize_currency'] = true; -/** - * - * - * @global string $cfg['Import']['xml_col_names'] - */ -$cfg['Import']['xls_col_names'] = false; - -/** - * - * - * @global string $cfg['Import']['xml_empty_rows'] - */ -$cfg['Import']['xls_empty_rows'] = true; - -/** - * - * - * @global string $cfg['Import']['xlsx_col_names'] - */ -$cfg['Import']['xlsx_col_names'] = false; - /******************************************************************************* * Schema export defaults */ diff --git a/libraries/config.values.php b/libraries/config.values.php index bc7786fc17..b4082ded56 100644 --- a/libraries/config.values.php +++ b/libraries/config.values.php @@ -174,7 +174,7 @@ $cfg_db['Export']['method'] = array( ); $cfg_db['Export']['format'] = array( 'codegen', 'csv', 'excel', 'htmlexcel','htmlword', 'latex', 'ods', - 'odt', 'pdf', 'sql', 'texytext', 'xls', 'xml', 'yaml' + 'odt', 'pdf', 'sql', 'texytext', 'xml', 'yaml' ); $cfg_db['Export']['compression'] = array('none', 'zip', 'gzip'); $cfg_db['Export']['charset'] = array_merge( @@ -203,8 +203,6 @@ $cfg_db['Export']['sql_insert_syntax'] = array( 'both' => __('both of the above'), 'none' => __('neither of the above') ); -$cfg_db['Export']['xls_null'] = 'short_string'; -$cfg_db['Export']['xlsx_null'] = 'short_string'; $cfg_db['Export']['htmlword_structure_or_data'] = $cfg_db['Export']['_sod_select']; $cfg_db['Export']['htmlword_null'] = 'short_string'; $cfg_db['Export']['ods_null'] = 'short_string'; diff --git a/libraries/config/messages.inc.php b/libraries/config/messages.inc.php index 8ddcc86585..bb459e03c1 100644 --- a/libraries/config/messages.inc.php +++ b/libraries/config/messages.inc.php @@ -226,10 +226,6 @@ $strConfigExport_sql_utc_time_name = __('Export time in UTC'); $strConfigExport_texytext_columns_name = __('Put columns names in the first row'); $strConfigExport_texytext_null_name = __('Replace NULL with'); $strConfigExport_texytext_structure_or_data_name = __('Dump table'); -$strConfigExport_xls_columns_name = __('Put columns names in the first row'); -$strConfigExport_xls_null_name = __('Replace NULL with'); -$strConfigExport_xlsx_columns_name = __('Put columns names in the first row'); -$strConfigExport_xlsx_null_name = __('Replace NULL with'); $strConfigForeignKeyDropdownOrder_desc = __( 'Sort order for items in a foreign-key dropdown box; [kbd]content[/kbd] is ' . 'the referenced data, [kbd]id[/kbd] is the key value.' @@ -402,8 +398,6 @@ $strConfigImport_sql_compatibility_name = __('SQL compatibility mode'); $strConfigImport_sql_no_auto_value_on_zero_name = __('Do not use AUTO_INCREMENT for zero values'); $strConfigImport_sql_read_as_multibytes_name = __('Read as multibytes'); -$strConfigImport_xls_col_names_name = __('Column names in first row'); -$strConfigImport_xlsx_col_names_name = __('Column names in first row'); $strConfigInitialSlidersState_name = __('Initial state for sliders'); $strConfigInsertRows_desc = __('How many rows can be inserted at one time.'); $strConfigInsertRows_name = __('Number of inserted rows'); @@ -869,6 +863,11 @@ $strConfigShowFunctionFields_desc = __( $strConfigShowFunctionFields_name = __('Show function fields'); $strConfigShowHint_desc = __('Whether to show hint or not.'); $strConfigShowHint_name = __('Show hint'); +$strConfigShowPhpInfo_desc = __( + 'Shows link to [a@https://php.net/manual/function.phpinfo.php]phpinfo()[/a] ' . + 'output.' +); +$strConfigShowPhpInfo_name = __('Show phpinfo() link'); $strConfigShowServerInfo_name = __('Show detailed MySQL server information'); $strConfigShowSQL_desc = __( 'Defines whether SQL queries generated by phpMyAdmin should be displayed.' diff --git a/libraries/config/setup.forms.php b/libraries/config/setup.forms.php index d4034d9118..2fb37d6535 100644 --- a/libraries/config/setup.forms.php +++ b/libraries/config/setup.forms.php @@ -203,6 +203,7 @@ $forms['Main_panel']['Startup'] = array( 'ShowCreateDb', 'ShowStats', 'ShowServerInfo', + 'ShowPhpInfo', 'ShowChgPassword'); $forms['Main_panel']['DbStructure'] = array( 'ShowDbStructureCharset', diff --git a/libraries/dbi/DBIMysqli.php b/libraries/dbi/DBIMysqli.php index fbc22495ea..e024339602 100644 --- a/libraries/dbi/DBIMysqli.php +++ b/libraries/dbi/DBIMysqli.php @@ -57,55 +57,6 @@ if (! defined('MYSQLI_TYPE_JSON')) { */ class DBIMysqli implements DBIExtension { - /** - * Helper function for connecting to the database server - * - * @param mysqli $link connection link - * @param string $host mysql hostname - * @param string $user mysql user name - * @param string $password mysql user password - * @param int $server_port server port - * @param string $server_socket server socket - * @param int $client_flags client flags of connection - * @param bool $persistent whether to use persistent connection - * - * @return bool - */ - private function _realConnect( - $link, $host, $user, $password, $server_port, - $server_socket, $client_flags = null, $persistent = false - ) { - global $cfg; - - // mysqli persistent connections - if ($cfg['PersistentConnections'] || $persistent) { - $host = 'p:' . $host; - } - - if ($client_flags === null) { - return mysqli_real_connect( - $link, - $host, - $user, - $password, - '', - $server_port, - $server_socket - ); - } else { - return mysqli_real_connect( - $link, - $host, - $user, - $password, - '', - $server_port, - $server_socket, - $client_flags - ); - } - } - /** * connects to the database server * @@ -174,13 +125,21 @@ class DBIMysqli implements DBIExtension } } - $return_value = $this->_realConnect( + if ($GLOBALS['cfg']['PersistentConnections']) { + $host = 'p:' . $server['host']; + } else { + $host = $server['host']; + } + + $return_value = mysqli_real_connect( $link, - $server['host'], + $host, $user, $password, + '', $server['port'], - $server['socket'] + $server['socket'], + $client_flags ); if ($return_value === false || is_null($return_value)) { diff --git a/libraries/insert_edit.lib.php b/libraries/insert_edit.lib.php index 2eb7d31830..10f6d9bdce 100644 --- a/libraries/insert_edit.lib.php +++ b/libraries/insert_edit.lib.php @@ -585,9 +585,6 @@ function PMA_getValueColumn($column, $backup_field, $column_name_appendix, } elseif ($GLOBALS['cfg']['LongtextDoubleTextarea'] && mb_strstr($column['pma_type'], 'longtext') ) { - $html_output = ' '; - $html_output .= ''; - $html_output .= '' . ''; $html_output .= PMA_getTextarea( $column, $backup_field, $column_name_appendix, $onChangeClause, $tabindex, $tabindex_for_value, $idindex, $text_dir, @@ -2658,14 +2655,8 @@ function PMA_getHtmlForIgnoreOption($row_id, $checked = true) */ function PMA_getHtmlForFunctionOption($column, $column_name_appendix) { - $longDoubleTextArea = $GLOBALS['cfg']['LongtextDoubleTextarea']; return '' . '' . $column['Field_title'] . ''; - $retval .= '