From 0490d204087560298e2df7fd2cc5831cf538c936 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Tue, 19 Jan 2016 10:48:32 +0100 Subject: [PATCH 1/5] Check for parameter before using it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Michal Čihař --- export.php | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/export.php b/export.php index b7942a34ac..b781eaa18d 100644 --- a/export.php +++ b/export.php @@ -163,11 +163,12 @@ if (!defined('TESTSUITE')) { } $table = $GLOBALS['table']; - // sanitize this parameter which will be used below in a file inclusion - $what = PMA_securePath($_POST['what']); PMA_Util::checkParameters(array('what', 'export_type')); + // sanitize this parameter which will be used below in a file inclusion + $what = PMA_securePath($_POST['what']); + // export class instance, not array of properties, as before /* @var $export_plugin ExportPlugin */ $export_plugin = PMA_getPlugin( From 1523c4b364ed0aa9951910ec87d9908f307fbd69 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Tue, 19 Jan 2016 11:10:10 +0100 Subject: [PATCH 2/5] Gracefully handle calling sql.php without SQL query MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Michal Čihař --- libraries/sql.lib.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/libraries/sql.lib.php b/libraries/sql.lib.php index 352800985b..20b0fe6fd7 100644 --- a/libraries/sql.lib.php +++ b/libraries/sql.lib.php @@ -2029,7 +2029,8 @@ function PMA_executeQueryAndGetQueryResponse($analyzed_sql_results, // (the parser never sets the 'union' key to 0). // Handling is also not required if we came from the "Sort by key" // drop-down. - if (PMA_isRememberSortingOrder($analyzed_sql_results) + if (! empty($analyzed_sql_results) + && PMA_isRememberSortingOrder($analyzed_sql_results) && empty($analyzed_sql_results['union']) && ! isset($_REQUEST['sort_by_key']) ) { From 897a844581761619d43f4e759bfe5ef117d400e1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Tue, 19 Jan 2016 11:19:03 +0100 Subject: [PATCH 3/5] Check for parameter before using it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Michal Čihař --- db_create.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/db_create.php b/db_create.php index 54440b62dd..76e9cb5737 100644 --- a/db_create.php +++ b/db_create.php @@ -17,6 +17,10 @@ if (! PMA_DRIZZLE) { } require 'libraries/build_html_for_db.lib.php'; +if (! isset($_POST['new_db'])) { + PMA_Util::checkParameters(array('new_db')); +} + /** * Defines the url to return to in case of error in a sql statement */ From a6ae24741e01bdbd4e3b7165183b800646fc8d73 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Tue, 19 Jan 2016 11:23:15 +0100 Subject: [PATCH 4/5] Validate parameters before use MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Michal Čihař --- gis_data_editor.php | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/gis_data_editor.php b/gis_data_editor.php index ac876da4d9..be13aeeb0e 100644 --- a/gis_data_editor.php +++ b/gis_data_editor.php @@ -23,6 +23,10 @@ require_once 'libraries/common.inc.php'; require_once 'libraries/gis/GIS_Factory.class.php'; require_once 'libraries/gis/GIS_Visualization.class.php'; +if (! isset($_REQUEST['field'])) { + PMA_Util::checkParameters(array('field')); +} + // Get data if any posted $gis_data = array(); if (PMA_isValid($_REQUEST['gis_data'], 'array')) { @@ -185,6 +189,9 @@ if ($geom_type == 'GEOMETRYCOLLECTION') { } for ($a = 0; $a < $geom_count; $a++) { + if (! isset($gis_data[$a])) { + continue; + } if ($geom_type == 'GEOMETRYCOLLECTION') { echo '

'; From 5359d9a968101a78c08a41cb4a77c9189595f7bb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michal=20=C4=8Ciha=C5=99?= Date: Tue, 19 Jan 2016 11:26:59 +0100 Subject: [PATCH 5/5] Check for parameter before using it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Michal Čihař --- schema_export.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/schema_export.php b/schema_export.php index ec1c4e0b54..b28ae6758f 100644 --- a/schema_export.php +++ b/schema_export.php @@ -22,6 +22,10 @@ require_once 'libraries/Index.class.php'; require_once 'libraries/pmd_common.php'; require_once 'libraries/plugin_interface.lib.php'; +if (! isset($_REQUEST['export_type'])) { + PMA_Util::checkParameters(array('export_type')); +} + /** * Include the appropriate Schema Class depending on $export_type * default is PDF