diff --git a/ChangeLog b/ChangeLog index 3f52a8ec55..121ae177a3 100644 --- a/ChangeLog +++ b/ChangeLog @@ -82,6 +82,9 @@ phpMyAdmin - ChangeLog - bug #3486970 [import] Exception on XML import - bug #3488777 [navi] $cfg['ShowTooltipAliasTB'] and blank names in navigation +3.4.10.1 (2012-02-18) +- [security] XSS in replication setup, see PMASA-2012-1 + 3.4.10.0 (2012-02-14) - bug #3460090 [interface] TextareaAutoSelect feature broken - patch #3375984 [export] PHP Array export might generate invalid php code diff --git a/js/replication.js b/js/replication.js index 04cf86e21e..f3fdb1e931 100644 --- a/js/replication.js +++ b/js/replication.js @@ -5,7 +5,7 @@ */ var random_server_id = Math.floor(Math.random() * 10000000); -var conf_prefix = "server-id=" + random_server_id + "
log-bin=mysql-bin
log-error=mysql-bin.err
"; +var conf_prefix = "server-id=" + random_server_id + "\nlog-bin=mysql-bin\nlog-error=mysql-bin.err\n"; function update_config() { @@ -17,16 +17,16 @@ function update_config() }); if ($('#db_select option:selected').size() == 0) { - $('#rep').html(conf_prefix); + $('#rep').text(conf_prefix); } else if ($('#db_type option:selected').val() == 'all') { - $('#rep').html(conf_prefix + conf_ignore + database_list); + $('#rep').text(conf_prefix + conf_ignore + database_list); } else { - $('#rep').html(conf_prefix + conf_do + database_list); + $('#rep').text(conf_prefix + conf_do + database_list); } } $(document).ready(function() { - $('#rep').html(conf_prefix); + $('#rep').text(conf_prefix); $('#db_type').change(update_config); $('#db_select').change(update_config);