The Internet, 2004-06-30
Greetings,
The phpMyAdmin development team announces
the availability of phpMyAdmin 2.5.7, patch level 1.
This version fixes the vulnerability dated 2004-06-29,
released on BUGTRAQ (see our Documentation.html, FAQ 8.2).
We would like to put emphasis on the disappointment we feel when a
bugreporter does not contact the authors of a software first, before
posting any exploits. The common way to report this, is to give the
developers a reasonable amount of time to respond to an exploit
before it is made public.
Download/support information on http://www.phpmyadmin.net.
Marc Delisle, for the team.
Hi,
Regarding this bug
,https://sourceforge.net/tracker/index.php?func=detail&aid=981359&group_id=23067&atid=377408
once again we face the problem of interpreting just what is meant by BINARY.
Exporting the mysql.user table, which, depending on the version, has
some fields marked BINARY, causes a problem *seeing* the expected
results, because they are in 0x format. Of course the correct data is there.
In MySQL:
As of MySQL 4.1, values in CHAR and VARCHAR columns are sorted and
compared according to the collation of the character set assigned to the
column. Before MySQL 4.1, sorting and comparison are based on the
collation of the server character set; you can declare the column with
the BINARY attribute to cause sorting and comparison to be case
sensitive using the underlying character code values rather then a
lexical ordering. BINARY doesn't affect how the column is stored or
retrieved.
http://dev.mysql.com/doc/mysql/en/CHAR.html
So, in the intention of MySQL's authors, BINARY does not mean that the
contents is binary.
In libraries/export/sql.php:
} else if (stristr($field_flags[$j], 'BINARY')) {
$values[] = '0x' . bin2hex($row[$j]);
As the user suggests, should we add an option "Use hexadecimal format
for BINARY" ?
Marc
_ __ __ _ _ _
_ __ | |__ _ __ | \/ |_ _ / \ __| |_ __ ___ (_)_ __
| '_ \| '_ \| '_ \| |\/| | | | | / _ \ / _` | '_ ` _ \| | '_ \
| |_) | | | | |_) | | | | |_| |/ ___ \ (_| | | | | | | | | | |
| .__/|_| |_| .__/|_| |_|\__, /_/ \_\__,_|_| |_| |_|_|_| |_|
|_| |_| |___/ 2.6.0-beta2
http://www.phpmyadmin.net
phpMyAdmin 2.6.0-beta2 - June 28th, 2004
========================================
A set of PHP-scripts to administrate MySQL over the Web.
--------------------------------------------------------
Announcement
------------
The phpMyAdmin Project is proud to announce the immediate availability of
the second beta release of phpMyAdmin 2.6.0.
Because of significant changes inside the database connection methods and
major improvements to the MySQL 4.1 compatibility, the team decided to
release this beta version from phpMyAdmin's current development code.
Supporting the new improved MySQL extension of php5 (MySQLi), phpMyAdmin has
made a giant step towards the upcoming PHP and MySQL versions.
For beta-1, phpMyAdmin has acquired a new CSS-based theme system. Two
themes are included, and can be chosen from the main menu. Full
documentation about the theme system will be done before the final
2.6.0 version.
As the new milestone should to be as stable as possible, any feedback about
2.6.0-beta1 would be appreciated. Please note, that it is not recommended
to run this testing release on production environments.
phpMyAdmin is a web administration tool for MySQL databases, intended to
handle a whole database server as well as a single database. Over the years,
it has become the most popular GUI for MySQL and is downloaded about 6,000
times a day, according to SourceForge.net.
The highlights of this release in detail:
Highlights
----------
Improvements:
* PHP 5 mysqli extension support
o better performance
o improved security
* Improved support for character sets
* Support for UTF-8 databases under MySQL 4.1
* Site-configurable header and footer
* Export:
o can add custom text to SQL export headers
o support for IF NOT EXISTS
o support for INSERT IGNORE and UPDATE IGNORE
o use unbuffered queries
o enclosing SQL export in a transaction
o selective row export
o improved ANSI compatibility
* Operations: now copy table defaults to "structure and data"
* Operations: database renaming
* Editing: option "Go back to this page"
* Sort: natural order (configurable)
* Search page: DISTINCT, IS NULL, IS NOT NULL, NOT LIKE, multiple choices for ENUM
* Left panel Logout link
* Popup calendar (date and time editing) for date, datetime and timestamp fields
* Set and alter collations for databases, tables and fields
* Security: Protection against cookie hijacking: encrypt also the user name, and set a time limit on the validity of encrypted password in the cookie
* "(Un)check all" link for privileges page
* (alpha2)Optional display of server choice as links
* (alpha2)Click on result row to mark the checkbox
* (alpha2)Show if BLOB is NULL
* (alpha2)Mouse cursor in db structure and table structure views
* (alpha2)Multiple row insert
* (alpha2)Search: new choice LIKE %...%
* (alpha2)Can now change the number of columns when adding fields
* (beta1)Graphical redesign (CSS-based) and theme management
* (beta1)InnoDB table defragmentation
* (beta1)Use one cookie per server
* (beta1)Default query can now contain field names
* (beta1)MySQL 4.1.2 support ("engine")
* (beta1)Export: experimental native Ms Excel support
* (beta1)Export: add FOREIGN_KEY_CHECKS=0
* (beta1)Auth: catch error when server is not responding
* (beta1)Operations: can now specify sort order for "Alter table order by"
* (beta1)Support for SHA1 function
* (beta1)Enable Relation view for InnoDB even if internal relations infrastructure is not in place
Fixes:
* Error parsing floating point digit and GRANT...TO
* Numeric field names
* Keyword field names become capitalized
* Substr transformation broken with utf-8
* CONSTRAINT error in MySQL 3.23.x
* MySQL charsets not added to WHERE clauses
* Export:
o on-the-fly compression problem
o CSV problem with double-byte characters
o UPDATE option does not work
* Editing:
o Invalid escaping of + in ENUM
o Undefined submit_mult
o Cannot edit first row when no primary key
o Cannot edit big table structure
o Multi-edit: changes are lost
o Editing of double and float numbers
o Charset information was lost when changing fields
* Invalid row count when emptying table
* Error on Delete link after a db search
* Interface: Icons not displayed for index management
* Problem when the query contains quotes
* Wrong detection of the CREATE privilege
* Problem when the bookmark table does not exist
* Password error when copying a user
* Search page and empty VARCHAR column
* IIS crash: header problem
* (alpha2)Invalid SQL on empty table export
* (alpha2)Multi-byte functions and windows- charsets
* (alpha2)Handling of USE in multiple queries
* (alpha2)Light mode undefined indices
* (alpha2)Consistent window layout for query window
* (alpha2)Missing localization for multi-row edit/delete/export
* (alpha2)Data dictionary: wrong formatting
* (alpha2)Uploading with UploadDir and open_basedir restriction
* (alpha2)Handling of complex sort queries
* (alpha2)Nested mode: collapsing problem
* (alpha2)Multi-edit: wrong tabindex ids
* (alpha2)Calendar: maximum values
* (alpha2)Privileges: wrong message when editing for non-existent db
* (alpha2)Parser and multibyte strings
* (alpha2)Browsing of foreign table: problem with encoding of the primary key reference
* (alpha2)Cookie login: avoid double frames
* (alpha2)Nested table now also works with aliases tablenames
* (beta1)Nested table: wrong group expanding (foreign characters)
* (beta1)Shorten query for edit/delete
* (beta1)Database search: use SELECT *
* (beta1)Error when deleting last row
* (beta1)Vertical mode: broken row highlighting
* (beta1)Better handling of MySQL comments (-- followed by any control character)
* (beta1)Wrong internal encoding for Hebrew
* (beta1)Ignore comments for SQL splitting
* (beta1)Synchronize left frame database drop-down box (number of tables)
* (beta2)Undefined index in left frame
* (beta2)Undefined variable db
* (beta2)Granting privileges does not take wildcards into account
* (beta2)Left frame does not reload on CREATE TABLE
* (beta2)Exporting and more than one foreign key
* (beta2)Javascript error when changing theme
* (beta2)Warning in mysql.dbi.lib.php
* (beta2)During table creation, query window tries to get the list of fields
Detailed list of changes since version 2.2.0 is available under
http://www.phpmyadmin.net/ChangeLog.txt
Availability
------------
This software is available under the GNU General Public License V2.0.
You can get the newest version at http://www.phpmyadmin.net/
Available file formats are: .zip, .tar.gz and .tar.bz2.
If you install phpMyAdmin on your system, it's recommended to
subscribe to the news mailing list by adding your address under
http://lists.sourceforge.net/lists/listinfo/phpmyadmin-news
This way, you will be informed of new updates and security fixes.
It is a read only list, and traffic is not greater than a few
mail every year.
Support and Documentation
-------------------------
The documentation is included in the software package as text and
HTML file, but can also be downloaded from:
http://www.phpmyadmin.net/documentation/
The software is provided as is without any express or implied
warranty, but there is a bugs tracker page under:
http://sourceforge.net/projects/phpmyadmin/ [click on "Bugs"]
In addition, there are also a number of discussion lists
related to phpMyAdmin. A list of mailing lists with archives
is available at:
http://sourceforge.net/mail/?group_id=23067 or
http://sourceforge.net/projects/phpmyadmin/ [click on "Lists"]
Finally, an users support forum is also available under:
http://sourceforge.net/forum/forum.php?forum_id=72909
Known bugs
----------
- phpMyAdmin SQL parser chokes on fieldnames with certain non-ASCII characters
(bugs #593598, #936161).
To be informed about new releases fixing these problems, please
subscribe to the news mailing list under
http://lists.sourceforge.net/lists/listinfo/phpmyadmin-news
or regularly check the sourceforge bugs tracker.
Donations
---------
The project accepts donations to help improve the product. There is
a "Donations" link on http://www.phpmyadmin.net.
Description
-----------
phpMyAdmin is intended to handle the administration of MySQL over the Web. It
can manage a whole MySQL server as well as a single database.
Currently it can:
- create and drop databases
- create, copy, drop, rename and alter tables
- do table maintenance
- delete, edit and add fields
- execute any SQL-statement, even batch-queries
- manage keys on fields
- load text files into tables
- create and read dumps of tables
- export data to CSV, XML and Latex formats
- administer multiple servers
- manage MySQL users and privileges
- check referential integrity
- using Query-by-example (QBE), create complex queries automatically
connecting required tables
- create PDF graphics of your Database layout
- search globally in a database or a subset of it
- communicate in 42 different languages
Authors & Copyright
-------------------
Copyright (C) 1998-2000 Tobias Ratschiller <tobias_at_ratschiller.com>
Copyright (C) 2001-2004 Marc Delisle <DelislMa_at_CollegeSherbrooke.qc.ca>
Olivier Müller <om_at_omnis.ch>
Robin Johnson <robbat2_at_users.sourceforge.net>
Alexander M. Turek <me_at_derrabus.de>
Michal Cihar <michal_at_cihar.com>
Garvin Hicking <me_at_supergarv.de>
Marcel Tschopp <ne0x_at_users.sourceforge.net>
+ many other people
(check the CREDITS section of our documentation)
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
EOF -- Alexander M. Turek and Marc Delisle/ 2004-06-28
Hi
I just noticed, that at least one recet addition was broken due to
redesign: Inputs for disabling foreign checking in exports went away. We
probably should check, whether there isn't also missing something else
what was recently added, so please check things you remember you added :-)
--
Michal Čihař | http://cihar.com
_ __ __ _ _ _
_ __ | |__ _ __ | \/ |_ _ / \ __| |_ __ ___ (_)_ __
| '_ \| '_ \| '_ \| |\/| | | | | / _ \ / _` | '_ ` _ \| | '_ \
| |_) | | | | |_) | | | | |_| |/ ___ \ (_| | | | | | | | | | |
| .__/|_| |_| .__/|_| |_|\__, /_/ \_\__,_|_| |_| |_|_|_| |_|
|_| |_| |___/ 2.6.0-beta1
http://www.phpmyadmin.net
phpMyAdmin 2.6.0-beta1 - June 24th, 2004
========================================
A set of PHP-scripts to administrate MySQL over the Web.
--------------------------------------------------------
Announcement
------------
The phpMyAdmin Project is proud to announce the immediate availability of
the first beta release of phpMyAdmin 2.6.0.
Because of significant changes inside the database connection methods and
major improvements to the MySQL 4.1 compatibility, the team decided to
release this beta version from phpMyAdmin's current development code.
Supporting the new improved MySQL extension of php5 (MySQLi), phpMyAdmin has
made a giant step towards the upcoming PHP and MySQL versions.
For beta-1, phpMyAdmin has acquired a new CSS-based theme system. Two
themes are included, and can be chosen from the main menu. Full
documentation about the theme system will be done before the final
2.6.0 version.
As the new milestone should to be as stable as possible, any feedback about
2.6.0-beta1 would be appreciated. Please note, that it is not recommended
to run this testing release on production environments.
phpMyAdmin is a web administration tool for MySQL databases, intended to
handle a whole database server as well as a single database. Over the years,
it has become the most popular GUI for MySQL and is downloaded about 6,000
times a day, according to SourceForge.net.
The highlights of this release in detail:
Highlights
----------
Improvements:
* PHP 5 mysqli extension support
o better performance
o improved security
* Improved support for character sets
* Support for UTF-8 databases under MySQL 4.1
* Site-configurable header and footer
* Export:
o can add custom text to SQL export headers
o support for IF NOT EXISTS
o support for INSERT IGNORE and UPDATE IGNORE
o use unbuffered queries
o enclosing SQL export in a transaction
o selective row export
o improved ANSI compatibility
* Operations: now copy table defaults to "structure and data"
* Operations: database renaming
* Editing: option "Go back to this page"
* Sort: natural order (configurable)
* Search page: DISTINCT, IS NULL, IS NOT NULL, NOT LIKE, multiple choices for ENUM
* Left panel Logout link
* Popup calendar (date and time editing) for date, datetime and timestamp fields
* Set and alter collations for databases, tables and fields
* Security: Protection against cookie hijacking: encrypt also the user name, and set a time limit on the validity of encrypted password in the cookie
* "(Un)check all" link for privileges page
* (alpha2)Optional display of server choice as links
* (alpha2)Click on result row to mark the checkbox
* (alpha2)Show if BLOB is NULL
* (alpha2)Mouse cursor in db structure and table structure views
* (alpha2)Multiple row insert
* (alpha2)Search: new choice LIKE %...%
* (alpha2)Can now change the number of columns when adding fields
* (beta1)Graphical redesign (CSS-based) and theme management
* (beta1)InnoDB table defragmentation
* (beta1)Use one cookie per server
* (beta1)Default query can now contain field names
* (beta1)MySQL 4.1.2 support ("engine")
* (beta1)Export: experimental native Ms Excel support
* (beta1)Export: add FOREIGN_KEY_CHECKS=0
* (beta1)Auth: catch error when server is not responding
* (beta1)Operations: can now specify sort order for "Alter table order by"
* (beta1)Support for SHA1 function
* (beta1)Enable Relation view for InnoDB even if internal relations infrastructure is not in place
Fixes:
* Error parsing floating point digit and GRANT...TO
* Numeric field names
* Keyword field names become capitalized
* Substr transformation broken with utf-8
* CONSTRAINT error in MySQL 3.23.x
* MySQL charsets not added to WHERE clauses
* Export:
o on-the-fly compression problem
o CSV problem with double-byte characters
o UPDATE option does not work
* Editing:
o Invalid escaping of + in ENUM
o Undefined submit_mult
o Cannot edit first row when no primary key
o Cannot edit big table structure
o Multi-edit: changes are lost
o Editing of double and float numbers
o Charset information was lost when changing fields
* Invalid row count when emptying table
* Error on Delete link after a db search
* Interface: Icons not displayed for index management
* Problem when the query contains quotes
* Wrong detection of the CREATE privilege
* Problem when the bookmark table does not exist
* Password error when copying a user
* Search page and empty VARCHAR column
* IIS crash: header problem
* (alpha2)Invalid SQL on empty table export
* (alpha2)Multi-byte functions and windows- charsets
* (alpha2)Handling of USE in multiple queries
* (alpha2)Light mode undefined indices
* (alpha2)Consistent window layout for query window
* (alpha2)Missing localization for multi-row edit/delete/export
* (alpha2)Data dictionary: wrong formatting
* (alpha2)Uploading with UploadDir and open_basedir restriction
* (alpha2)Handling of complex sort queries
* (alpha2)Nested mode: collapsing problem
* (alpha2)Multi-edit: wrong tabindex ids
* (alpha2)Calendar: maximum values
* (alpha2)Privileges: wrong message when editing for non-existent db
* (alpha2)Parser and multibyte strings
* (alpha2)Browsing of foreign table: problem with encoding of the primary key reference
* (alpha2)Cookie login: avoid double frames
* (alpha2)Nested table now also works with aliases tablenames
* (beta1)Nested table: wrong group expanding (foreign characters)
* (beta1)Shorten query for edit/delete
* (beta1)Database search: use SELECT *
* (beta1)Error when deleting last row
* (beta1)Vertical mode: broken row highlighting
* (beta1)Better handling of MySQL comments (-- followed by any control character)
* (beta1)Wrong internal encoding for Hebrew
* (beta1)Ignore comments for SQL splitting
* (beta1)Synchronize left frame database drop-down box (number of tables)
Detailed list of changes since version 2.2.0 is available under
http://www.phpmyadmin.net/ChangeLog.txt
Availability
------------
This software is available under the GNU General Public License V2.0.
You can get the newest version at http://www.phpmyadmin.net/
Available file formats are: .zip, .tar.gz and .tar.bz2.
If you install phpMyAdmin on your system, it's recommended to
subscribe to the news mailing list by adding your address under
http://lists.sourceforge.net/lists/listinfo/phpmyadmin-news
This way, you will be informed of new updates and security fixes.
It is a read only list, and traffic is not greater than a few
mail every year.
Support and Documentation
-------------------------
The documentation is included in the software package as text and
HTML file, but can also be downloaded from:
http://www.phpmyadmin.net/documentation/
The software is provided as is without any express or implied
warranty, but there is a bugs tracker page under:
http://sourceforge.net/projects/phpmyadmin/ [click on "Bugs"]
In addition, there are also a number of discussion lists
related to phpMyAdmin. A list of mailing lists with archives
is available at:
http://sourceforge.net/mail/?group_id=23067 or
http://sourceforge.net/projects/phpmyadmin/ [click on "Lists"]
Finally, an users support forum is also available under:
http://sourceforge.net/forum/forum.php?forum_id=72909
Known bugs
----------
- phpMyAdmin SQL parser chokes on fieldnames with certain non-ASCII characters
(bugs #593598, #936161).
To be informed about new releases fixing these problems, please
subscribe to the news mailing list under
http://lists.sourceforge.net/lists/listinfo/phpmyadmin-news
or regularly check the sourceforge bugs tracker.
Donations
---------
The project accepts donations to help improve the product. There is
a "Donations" link on http://www.phpmyadmin.net.
Description
-----------
phpMyAdmin is intended to handle the administration of MySQL over the Web. It
can manage a whole MySQL server as well as a single database.
Currently it can:
- create and drop databases
- create, copy, drop, rename and alter tables
- do table maintenance
- delete, edit and add fields
- execute any SQL-statement, even batch-queries
- manage keys on fields
- load text files into tables
- create and read dumps of tables
- export data to CSV, XML and Latex formats
- administer multiple servers
- manage MySQL users and privileges
- check referential integrity
- using Query-by-example (QBE), create complex queries automatically
connecting required tables
- create PDF graphics of your Database layout
- search globally in a database or a subset of it
- communicate in 42 different languages
Authors & Copyright
-------------------
Copyright (C) 1998-2000 Tobias Ratschiller <tobias_at_ratschiller.com>
Copyright (C) 2001-2004 Marc Delisle <DelislMa_at_CollegeSherbrooke.qc.ca>
Olivier Müller <om_at_omnis.ch>
Robin Johnson <robbat2_at_users.sourceforge.net>
Alexander M. Turek <me_at_derrabus.de>
Michal Cihar <michal_at_cihar.com>
Garvin Hicking <me_at_supergarv.de>
Marcel Tschopp <ne0x_at_users.sourceforge.net>
+ many other people
(check the CREDITS section of our documentation)
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
EOF -- Alexander M. Turek and Marc Delisle/ 2004-06-24
Hi Marc and all
Just updated my copy and ... should't be browsing pointers enabled by
default (as it was IMHO before)?
--
Michal Čihař | http://cihar.com