Go to file
Michal Čihař d03954bf9c Enable LOAD DATA LOCAL INFILE only when needed
There is no need to have this feature allowed for normal SQL queries, it
can lead to leaking sensitive files from the web server. It's enough to
enable it only in LDI import plugin, where we control what queries are
executed.

Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-23 08:59:02 +02:00
doc Backport cookie encryption from 4.6 branch 2016-07-22 14:40:02 +02:00
examples Hide session error messages to avoid FPD 2016-07-12 12:37:19 +02:00
js Fixed rendering of chart of columns with HTML inside 2016-06-22 13:10:37 +02:00
libraries Enable LOAD DATA LOCAL INFILE only when needed 2016-07-23 08:59:02 +02:00
PMAStandard
po Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
scripts Use https for wiki links 2016-07-09 09:10:57 +02:00
setup Backport cookie encryption from 4.6 branch 2016-07-22 14:40:02 +02:00
test Sanitize filename on SHP import 2016-07-22 11:49:35 +02:00
themes Expand the navigation and highlight the current database or table/view 2013-08-30 12:30:05 +05:30
.gitignore
.travis.yml Try to run Travis own phpunit 2016-01-28 14:12:37 +01:00
browse_foreigners.php Bug #4048 Cannot select foreign value in Search 2013-08-07 08:27:34 -04:00
build.xml Fix bug "#3853 Blowfish implementation might be broken" by replacing the 2013-04-01 07:04:25 -04:00
ChangeLog Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
changelog.php Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
chk_rel.php
composer.json Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
config.sample.inc.php Backport cookie encryption from 4.6 branch 2016-07-22 14:40:02 +02:00
db_create.php
db_datadict.php The data dictionary is a print view page 2012-12-09 13:47:52 +00:00
db_events.php
db_export.php bug #3948 Server export problems 2013-05-21 16:44:41 +05:30
db_import.php
db_operations.php #4144 "DROP DATABASE" displays wrong database name FIX 2013-10-27 13:30:46 +05:30
db_printview.php
db_qbe.php
db_routines.php
db_search.php Upgraded to jquery-ui-timepicker-addon 1.1.1 2013-01-01 11:50:04 -05:00
db_sql.php
db_structure.php Upgraded to jquery-ui-timepicker-addon 1.1.1 2013-01-01 11:50:04 -05:00
db_tracking.php Bug #3960 NavigationBarIconic config not honored 2013-06-21 10:00:41 -04:00
db_triggers.php
export.php bug #4095 NUL symbols added to the end of database dump file 2013-09-28 12:29:55 -04:00
favicon.ico
file_echo.php Remove no longer used code 2016-07-22 16:46:32 +02:00
gis_data_editor.php
import_status.php Update session upload progress bug comment in import_status.php 2013-06-09 16:46:01 +02:00
import.php Enable LOAD DATA LOCAL INFILE only when needed 2016-07-23 08:59:02 +02:00
index.php Backport cookie encryption from 4.6 branch 2016-07-22 14:40:02 +02:00
LICENSE
license.php
navigation.php use uppercase for AJAX acronym 2013-01-21 00:34:23 +01:00
phpinfo.php Sent CSP headers for phpinfo 2016-06-30 09:51:38 +02:00
phpmyadmin.css.php
phpunit.xml.dist
phpunit.xml.nocoverage
pmd_display_field.php Fix setting display column 2012-12-09 13:50:40 +05:30
pmd_general.php Drop some inline html 2013-01-10 13:55:25 +01:00
pmd_pdf.php Ensure page number is integer 2016-07-12 16:49:15 +02:00
pmd_relation_new.php
pmd_relation_upd.php
pmd_save_pos.php
prefs_forms.php
prefs_manage.php
print.css
querywindow.php Fixed menu display in querywindow 2012-11-25 14:05:04 +00:00
README Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
README.rst Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
robots.txt
schema_edit.php
schema_export.php [security] Fix control user SQL injection in schema_export.php, see PMASA-2015 2013-07-23 08:48:53 -04:00
server_binlog.php Escape binary log name 2016-06-17 14:53:31 +02:00
server_collations.php
server_databases.php bug #3993 Sorting in database overview with statistics doesn't work 2013-08-28 08:27:02 -04:00
server_engines.php Added microhistory metadata to some links 2012-11-25 20:37:36 +00:00
server_export.php bug #3948 Server export problems 2013-05-21 16:44:41 +05:30
server_import.php
server_plugins.php
server_privileges.php Fix bug#3922, user privileges, in QA_4_0 2013-06-12 18:10:38 +05:30
server_replication.php Fix bug #3907 undefined variables, function parameter problems 2013-05-13 11:27:56 +02:00
server_sql.php
server_status_advisor.php Fix bug #3907 undefined variables, function parameter problems 2013-05-13 11:27:56 +02:00
server_status_monitor.php Drop no longer needed date.js 2013-07-08 12:59:28 +02:00
server_status_queries.php remove unused variables 2013-01-25 13:08:49 +01:00
server_status_variables.php Properly escape MySQL status variables 2016-07-10 18:06:25 +02:00
server_status.php [security] Fix stored XSS in Server status monitor, see PMASA-2013-9 2013-07-07 15:55:18 +02:00
server_variables.php Do not double HTML encode URL 2013-08-07 14:39:39 +02:00
show_config_errors.php
sql.php Fix bug#4059: Running delete query asks for confirmation but says it was already executed 2013-10-28 01:53:50 +05:30
tbl_addfield.php Limit maximal numver of fields to 4096 2016-07-22 16:00:23 +02:00
tbl_change.php PMA_Table::analyzeStructure() method to centralize the analysis of the structure of a view/table 2013-05-13 23:11:30 +05:30
tbl_chart.php Check whether operands are identical. Otherwise 0 makes the condition true 2013-03-25 21:03:52 +05:30
tbl_create.php Limit maximal numver of fields to 4096 2016-07-22 16:00:23 +02:00
tbl_export.php Add unset() statement to help for future refactoring 2013-05-26 09:52:34 -04:00
tbl_get_field.php bug #4090 Downloading BLOB downloads page template 2013-09-14 06:24:32 -04:00
tbl_gis_visualization.php HTTPS will not see OpenStreetMaps due to CSP. So do not show the checkbox also 2013-04-14 23:38:30 +05:30
tbl_import.php
tbl_indexes.php Bug #3839 Index comment is supported only starting with MySQL 5.5 2013-03-25 19:43:29 -04:00
tbl_move_copy.php
tbl_operations.php No need to do index checking if the table is not InnoDB 2013-09-25 09:32:13 +05:30
tbl_printview.php bug #4578 XSS vulnerability in table print view 2014-11-04 16:05:06 +05:30
tbl_relation.php bug #4517 [security] XSS in relation view 2014-08-16 22:00:13 +05:30
tbl_replace.php Typo Fix in comment 2013-10-29 23:33:00 +05:30
tbl_row_action.php
tbl_select.php Upgraded to jquery-ui-timepicker-addon 1.1.1 2013-01-01 11:50:04 -05:00
tbl_sql.php
tbl_structure.php Bug #3960 NavigationBarIconic config not honored 2013-06-21 10:00:41 -04:00
tbl_tracking.php Validate serialized data before unserializing 2016-07-12 16:25:20 +02:00
tbl_triggers.php
tbl_zoom_select.php Fix XSS in zoom search 2016-02-29 12:33:47 +11:00
themes.php Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
transformation_overview.php
transformation_wrapper.php Escape HTML markup in transformation wrapper 2016-07-13 10:34:19 +02:00
url.php Send standard set of HTTP headers on redirect 2016-07-22 12:22:53 +02:00
user_password.php remove unused variable and simplify code 2013-01-25 13:13:35 +01:00
version_check.php Use https to access phpmyadmin.net 2016-07-18 16:20:34 +02:00
view_create.php escape query in error message 2013-05-29 21:13:32 +02:00
view_operations.php bug #3988 Rename view is not working 2013-09-18 13:06:44 -04:00
webapp.php

phpMyAdmin - Readme
===================

Version 4.0.10.16

A set of PHP-scripts to manage MySQL over the web.

https://www.phpmyadmin.net/

Copyright
---------

Copyright (C) 1998-2000
    Tobias Ratschiller <tobias_at_ratschiller.com>

Copyright (C) 2001-2014
    Marc Delisle <marc_at_infomarc.info>
    Olivier Müller <om_at_omnis.ch>
    Robin Johnson <robbat2_at_users.sourceforge.net>
    Alexander M. Turek <me_at_derrabus.de>
    Michal Čihař <michal_at_cihar.com>
    Garvin Hicking <me_at_supergarv.de>
    Michael Keck <mkkeck_at_users.sourceforge.net>
    Sebastian Mendel <cybot_tm_at_users.sourceforge.net>
    [check documentation for more details]

License
-------

This program is free software; you can redistribute it and/or modify it under
the terms of the GNU General Public License version 2, as published by the
Free Software Foundation.

This program is distributed in the hope that it will be useful, but WITHOUT
ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more
details.

You should have received a copy of the GNU General Public License
along with this program.  If not, see <http://www.gnu.org/licenses/>.

Requirements
------------

* PHP 5.2 or later
* MySQL 5.0 or later
* a web-browser (doh!)

Summary
-------

phpMyAdmin is intended to handle the administration of MySQL over the web.
For a summary of features, please see the documentation in the doc folder.

Download
--------

You can get the newest version at https://www.phpmyadmin.net/.

More Information
----------------

Please see the documentation in the doc folder.

Support
-------

See reference about support forums under https://www.phpmyadmin.net/


Enjoy!
------

The phpMyAdmin Devel team


PS:

Please, don't send us emails with question like "How do I compile PHP with
MySQL-support". We just don't have the time to be your free help desk.

Please send your questions to the appropriate mailing lists / forums.  Before
contacting us, please read the documentation (especially the FAQ part).