[Phpmyadmin-git] [phpmyadmin/phpmyadmin] 0d4adb: [security] possible XSRF on several pages

Michal Čihař mcihar at suse.cz
Wed Apr 11 11:10:57 CEST 2012


  Branch: refs/heads/QA_3_0
  Home:   https://github.com/phpmyadmin/phpmyadmin
  Commit: 0d4adbfc1996c7d715b0ac9fa39a2ac14d8b28ad
      https://github.com/phpmyadmin/phpmyadmin/commit/0d4adbfc1996c7d715b0ac9fa39a2ac14d8b28ad
  Author: Michal Čihař <michal at cihar.com>
  Date:   2008-12-09 (Tue, 09 Dec 2008)

  Changed paths:
    M ChangeLog
  M libraries/db_table_exists.lib.php

  Log Message:
  -----------
  [security] possible XSRF on several pages


  Commit: 2748fc9fac256f713be6a22a01fd0db373a8c545
      https://github.com/phpmyadmin/phpmyadmin/commit/2748fc9fac256f713be6a22a01fd0db373a8c545
  Author: Michal Čihař <michal at cihar.com>
  Date:   2008-12-09 (Tue, 09 Dec 2008)

  Changed paths:
    M ChangeLog
  M libraries/db_table_exists.lib.php

  Log Message:
  -----------
  Forgotten branch.


  Commit: 18d793440516f560ad8dd6c172cc05fc39380d86
      https://github.com/phpmyadmin/phpmyadmin/commit/18d793440516f560ad8dd6c172cc05fc39380d86
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2008-12-09 (Tue, 09 Dec 2008)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.9.4


  Commit: e70d7b4332d55ac304633a14045d5d153490e566
      https://github.com/phpmyadmin/phpmyadmin/commit/e70d7b4332d55ac304633a14045d5d153490e566
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M scripts/setup.php

  Log Message:
  -----------
  Do not output unescaped chars to generated configuration file.


  Commit: 460a649dbcc47065fbf01bbc14392c3fc6ea161b
      https://github.com/phpmyadmin/phpmyadmin/commit/460a649dbcc47065fbf01bbc14392c3fc6ea161b
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M scripts/setup.php

  Log Message:
  -----------
  Do not output unescaped chars to generated configuration file.


  Commit: c05d94cdd92559f3eb89175d440dc3535dacb00b
      https://github.com/phpmyadmin/phpmyadmin/commit/c05d94cdd92559f3eb89175d440dc3535dacb00b
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M libraries/display_export.lib.php

  Log Message:
  -----------
  Escape special chars when displaying filename template cookies.


  Commit: 36ddf8b61ee17cb37c0cba666179376a2d965c61
      https://github.com/phpmyadmin/phpmyadmin/commit/36ddf8b61ee17cb37c0cba666179376a2d965c61
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M libraries/display_export.lib.php

  Log Message:
  -----------
  Escape special chars when displaying filename template cookies.


  Commit: 649d13e234cb7bcd7d00aea03a131ca2041f7245
      https://github.com/phpmyadmin/phpmyadmin/commit/649d13e234cb7bcd7d00aea03a131ca2041f7245
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M Documentation.html
  M config.sample.inc.php
  M main.php
  M scripts/setup.php

  Log Message:
  -----------
  Use official names for wiki (wiki.phpmyadmin.net) and demo server (demo.phpmyadmin.net).


  Commit: aeae6df369ff6872b4dd2091fb5bf5d77a012b7d
      https://github.com/phpmyadmin/phpmyadmin/commit/aeae6df369ff6872b4dd2091fb5bf5d77a012b7d
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M Documentation.html
  M config.sample.inc.php
  M main.php
  M scripts/setup.php

  Log Message:
  -----------
  Use official names for wiki (wiki.phpmyadmin.net) and demo server (demo.phpmyadmin.net).


  Commit: 8e18c2d8df6c4185df8765ed216ef4a452686575
      https://github.com/phpmyadmin/phpmyadmin/commit/8e18c2d8df6c4185df8765ed216ef4a452686575
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.9.5


  Commit: 7b5ec357bcc51f8950439b8f0f4a1187bfb6364e
      https://github.com/phpmyadmin/phpmyadmin/commit/7b5ec357bcc51f8950439b8f0f4a1187bfb6364e
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-03-24 (Tue, 24 Mar 2009)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  2.11.9.5


  Commit: a6a45d71385b08c34624136983aad4b14db01baf
      https://github.com/phpmyadmin/phpmyadmin/commit/a6a45d71385b08c34624136983aad4b14db01baf
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-25 (Wed, 25 Mar 2009)

  Changed paths:
    M Documentation.html

  Log Message:
  -----------
  Document removal of config directory after configuring phpMyAdmin.


  Commit: 72f86848c373d21f78713b3cc0b81faf099c6d6e
      https://github.com/phpmyadmin/phpmyadmin/commit/72f86848c373d21f78713b3cc0b81faf099c6d6e
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-03-25 (Wed, 25 Mar 2009)

  Changed paths:
    M Documentation.html

  Log Message:
  -----------
  Document removal of config directory after configuring phpMyAdmin.


  Commit: deb1b31cae916158c1770cb0d085ed10800604bd
      https://github.com/phpmyadmin/phpmyadmin/commit/deb1b31cae916158c1770cb0d085ed10800604bd
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-10-12 (Mon, 12 Oct 2009)

  Changed paths:
    M ChangeLog
  M db_operations.php
  M pdf_pages.php
  M pmd_pdf.php

  Log Message:
  -----------
  [security] XSS and SQL injection


  Commit: 212daad0c082dfb853e3a4098838781a96b2ce1f
      https://github.com/phpmyadmin/phpmyadmin/commit/212daad0c082dfb853e3a4098838781a96b2ce1f
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-10-12 (Mon, 12 Oct 2009)

  Changed paths:
    M ChangeLog
  M db_operations.php
  M pdf_pages.php
  M pmd_pdf.php

  Log Message:
  -----------
  [security] XSS and SQL injection


  Commit: 628b38373bd5634b8fb8eb0889b65707dfe90321
      https://github.com/phpmyadmin/phpmyadmin/commit/628b38373bd5634b8fb8eb0889b65707dfe90321
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-10-12 (Mon, 12 Oct 2009)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.9.6 release


  Commit: 719e0dce659f4a452d06a26e9432d888531a6e7b
      https://github.com/phpmyadmin/phpmyadmin/commit/719e0dce659f4a452d06a26e9432d888531a6e7b
  Author: Michal Čihař <michal at cihar.com>
  Date:   2009-12-07 (Mon, 07 Dec 2009)

  Changed paths:
    M ChangeLog
  M scripts/setup.php

  Log Message:
  -----------
  [setup] avoid usage of (un)serialize, what might be unsafe in some cases


  Commit: 13fc94b84497cae38084b387bc583a9781b7049b
      https://github.com/phpmyadmin/phpmyadmin/commit/13fc94b84497cae38084b387bc583a9781b7049b
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-12-07 (Mon, 07 Dec 2009)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11-dev


  Commit: 8535d48ae9c8ea554393802db68dbc9ec571b864
      https://github.com/phpmyadmin/phpmyadmin/commit/8535d48ae9c8ea554393802db68dbc9ec571b864
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2009-12-07 (Mon, 07 Dec 2009)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.10 release


  Commit: f175026ff0d873c5c73bc841697596e995e271b9
      https://github.com/phpmyadmin/phpmyadmin/commit/f175026ff0d873c5c73bc841697596e995e271b9
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2009-12-28 (Mon, 28 Dec 2009)

  Changed paths:
    M ChangeLog
  M index.php

  Log Message:
  -----------
  [core] Fix broken cleanup of $_GET


  Commit: 8ae41bbc0238581d5e0e692e4dc67e35ded00170
      https://github.com/phpmyadmin/phpmyadmin/commit/8ae41bbc0238581d5e0e692e4dc67e35ded00170
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-03-11 (Thu, 11 Mar 2010)

  Changed paths:
    M README

  Log Message:
  -----------
  Merge remote branch 'origin/MAINT_2_11_10' into QA_2_11

Conflicts:
	ChangeLog
	Documentation.html
	README
	libraries/Config.class.php
	translators.html


  Commit: 4951fd1c854d88e22935fd55d342fcb1670dc8e4
      https://github.com/phpmyadmin/phpmyadmin/commit/4951fd1c854d88e22935fd55d342fcb1670dc8e4
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M db_sql.php

  Log Message:
  -----------
  Fix XSS on delimiter in db_sql.php.


  Commit: 110c44a7a3117b94b065742606cc6f7bc05f8cd5
      https://github.com/phpmyadmin/phpmyadmin/commit/110c44a7a3117b94b065742606cc6f7bc05f8cd5
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M tbl_sql.php

  Log Message:
  -----------
  Fix XSS on delimiter in tbl_sql.php.


  Commit: 08e27b89077df26a0f7f0390322bbe80e0437aa1
      https://github.com/phpmyadmin/phpmyadmin/commit/08e27b89077df26a0f7f0390322bbe80e0437aa1
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M server_databases.php

  Log Message:
  -----------
  Secure handling of sort_by and sort_order in server_databases.php.


  Commit: c910f4c9ec9af876675d96df3fa65d7fc4551cc6
      https://github.com/phpmyadmin/phpmyadmin/commit/c910f4c9ec9af876675d96df3fa65d7fc4551cc6
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M libraries/database_interface.lib.php

  Log Message:
  -----------
  Fix handling of unknown sort order.


  Commit: c69fca50ee81ff74cda860aad339d4185d32e194
      https://github.com/phpmyadmin/phpmyadmin/commit/c69fca50ee81ff74cda860aad339d4185d32e194
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M libraries/sanitizing.lib.php

  Log Message:
  -----------
  Add option to escape PMA_sanitize output.

This is required when it is used in form values.


  Commit: a4a54da173440d4c5097aececef56c28c14dc52e
      https://github.com/phpmyadmin/phpmyadmin/commit/a4a54da173440d4c5097aececef56c28c14dc52e
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M sql.php

  Log Message:
  -----------
  Escape html chars in form values.


  Commit: 0fe30236fac3c00ff123b9d48cc0b4b2ff6a7746
      https://github.com/phpmyadmin/phpmyadmin/commit/0fe30236fac3c00ff123b9d48cc0b4b2ff6a7746
  Author: Michal Čihař <michal at cihar.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M libraries/sanitizing.lib.php

  Log Message:
  -----------
  Document PMA_sanitize.


  Commit: 8b8ce64792bb981cefc37a19f29f28f112df1c16
      https://github.com/phpmyadmin/phpmyadmin/commit/8b8ce64792bb981cefc37a19f29f28f112df1c16
  Author: Michal Čihař <michal at cihar.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M server_privileges.php

  Log Message:
  -----------
  Fix XSS on dbname.


  Commit: 1fe1aa6c0e2d85bed1343f4be21d672368e0a9c1
      https://github.com/phpmyadmin/phpmyadmin/commit/1fe1aa6c0e2d85bed1343f4be21d672368e0a9c1
  Author: Michal Čihař <michal at cihar.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M server_privileges.php

  Log Message:
  -----------
  Fix XSS on tablename and pred_tablename.


  Commit: 8b7f07cd954221f276ab11e2c3d98f18deb2f551
      https://github.com/phpmyadmin/phpmyadmin/commit/8b7f07cd954221f276ab11e2c3d98f18deb2f551
  Author: Michal Čihař <michal at cihar.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M server_privileges.php

  Log Message:
  -----------
  Fix XSS on username.


  Commit: a7c004d8d4069ca3c7d1c221f37b9cab39e36aaf
      https://github.com/phpmyadmin/phpmyadmin/commit/a7c004d8d4069ca3c7d1c221f37b9cab39e36aaf
  Author: Michal Čihař <michal at cihar.com>
  Date:   2010-08-18 (Wed, 18 Aug 2010)

  Changed paths:
    M server_privileges.php

  Log Message:
  -----------
  Fix XSS on hostname.


  Commit: 30c83acddb58d3bbf940b5f9ec28abf5b235f4d2
      https://github.com/phpmyadmin/phpmyadmin/commit/30c83acddb58d3bbf940b5f9ec28abf5b235f4d2
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-19 (Thu, 19 Aug 2010)

  Changed paths:
    M scripts/setup.php

  Log Message:
  -----------
  Properly escape key name when generating config file.


  Commit: 4a50055d52cb1d6ba125b743b0eb422d5549b9c9
      https://github.com/phpmyadmin/phpmyadmin/commit/4a50055d52cb1d6ba125b743b0eb422d5549b9c9
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M libraries/sqlparser.lib.php

  Log Message:
  -----------
  Fix XSS with $cfg['SQP']['fmtType'] = 'text'.


  Commit: 0fd0512c9b7344abad60ab9effb7b7537b2b5d08
      https://github.com/phpmyadmin/phpmyadmin/commit/0fd0512c9b7344abad60ab9effb7b7537b2b5d08
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M libraries/common.lib.php

  Log Message:
  -----------
  Fix XSS on error with very long query.


  Commit: 2051a861f8a968dafc297650036cc7e640a18887
      https://github.com/phpmyadmin/phpmyadmin/commit/2051a861f8a968dafc297650036cc7e640a18887
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M libraries/common.lib.php

  Log Message:
  -----------
  Fix possible XSS on IIS redirect page.


  Commit: e7d10a6d53582abcf20455ad0051048a991023af
      https://github.com/phpmyadmin/phpmyadmin/commit/e7d10a6d53582abcf20455ad0051048a991023af
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M error.php

  Log Message:
  -----------
  Avoid information disclossure on error.


  Commit: a88dbaf305a44107ffb557e9d93512792744af84
      https://github.com/phpmyadmin/phpmyadmin/commit/a88dbaf305a44107ffb557e9d93512792744af84
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M libraries/dbi/mysql.dbi.lib.php
  M libraries/dbi/mysqli.dbi.lib.php

  Log Message:
  -----------
  Escape error message coming from MySQL to avoid XSS on bad parameters.


  Commit: 437e00ef2eec5fbc743f652c93d90b3853dcf825
      https://github.com/phpmyadmin/phpmyadmin/commit/437e00ef2eec5fbc743f652c93d90b3853dcf825
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  Changelog.


  Commit: b1cb5590eefd2977bdb3a6e45796d5a4189e95ad
      https://github.com/phpmyadmin/phpmyadmin/commit/b1cb5590eefd2977bdb3a6e45796d5a4189e95ad
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  Set version to 2.11.10.1.


  Commit: c1865ca7b863bd919b91313806ea47570de8347c
      https://github.com/phpmyadmin/phpmyadmin/commit/c1865ca7b863bd919b91313806ea47570de8347c
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-20 (Fri, 20 Aug 2010)

  Changed paths:
    M ChangeLog
  M db_sql.php
  M error.php
  M libraries/common.lib.php
  M libraries/database_interface.lib.php
  M libraries/dbi/mysql.dbi.lib.php
  M libraries/dbi/mysqli.dbi.lib.php
  M libraries/sanitizing.lib.php
  M libraries/sqlparser.lib.php
  M scripts/setup.php
  M server_databases.php
  M server_privileges.php
  M sql.php
  M tbl_sql.php

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_10' into QA_2_11

Conflicts:
	ChangeLog
	Documentation.html
	README
	libraries/Config.class.php
	translators.html


  Commit: 20c87804372c425664211babe22ac918629acdc1
      https://github.com/phpmyadmin/phpmyadmin/commit/20c87804372c425664211babe22ac918629acdc1
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-08-30 (Mon, 30 Aug 2010)

  Changed paths:
    M ChangeLog
  M libraries/sqlparser.lib.php

  Log Message:
  -----------
  bug #3054458 [core] Fixed displaying number of rows.


  Commit: 0e4369a8d2e4dbd1f3e0493b75b4f85eb1f0f908
      https://github.com/phpmyadmin/phpmyadmin/commit/0e4369a8d2e4dbd1f3e0493b75b4f85eb1f0f908
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-08-31 (Tue, 31 Aug 2010)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11-rc1


  Commit: 510a5c0b69bfd19610a3116d530db02317e40db5
      https://github.com/phpmyadmin/phpmyadmin/commit/510a5c0b69bfd19610a3116d530db02317e40db5
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-08-31 (Tue, 31 Aug 2010)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.12-dev


  Commit: 5341872a9163c609abbf88cd8ea1dc1c6884dc6d
      https://github.com/phpmyadmin/phpmyadmin/commit/5341872a9163c609abbf88cd8ea1dc1c6884dc6d
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-09-01 (Wed, 01 Sep 2010)

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_11' into QA_2_11


  Commit: 134cbbd490eddaaf1efd97e2c15922eac2d65fab
      https://github.com/phpmyadmin/phpmyadmin/commit/134cbbd490eddaaf1efd97e2c15922eac2d65fab
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-09-01 (Wed, 01 Sep 2010)

  Changed paths:
    M README

  Log Message:
  -----------
  Update year.


  Commit: e6aeaf1925be0804e068d50b8c193d8b13f80ced
      https://github.com/phpmyadmin/phpmyadmin/commit/e6aeaf1925be0804e068d50b8c193d8b13f80ced
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-09-07 (Tue, 07 Sep 2010)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11 release


  Commit: b073a5a10f60581083f1b37f86455b0be8cbdfd6
      https://github.com/phpmyadmin/phpmyadmin/commit/b073a5a10f60581083f1b37f86455b0be8cbdfd6
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-09-07 (Tue, 07 Sep 2010)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  2.11.11 release


  Commit: 8b2f1bc55dfe4599f30398205638326345878b8d
      https://github.com/phpmyadmin/phpmyadmin/commit/8b2f1bc55dfe4599f30398205638326345878b8d
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-09-08 (Wed, 08 Sep 2010)

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_11' into QA_2_11


  Commit: 80766a95caae8dec56e52efdb20abfd3867205c5
      https://github.com/phpmyadmin/phpmyadmin/commit/80766a95caae8dec56e52efdb20abfd3867205c5
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2010-09-16 (Thu, 16 Sep 2010)

  Changed paths:
    M lang/polish-iso-8859-2.inc.php
  M lang/polish-utf-8.inc.php
  M lang/polish-windows-1250.inc.php

  Log Message:
  -----------
  Polish update (#3062617).


  Commit: e1f4901ffc400b6d2df15eac0ba5015fe48a27c4
      https://github.com/phpmyadmin/phpmyadmin/commit/e1f4901ffc400b6d2df15eac0ba5015fe48a27c4
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2010-11-26 (Fri, 26 Nov 2010)

  Changed paths:
    M libraries/common.lib.php

  Log Message:
  -----------
  bug #3115519: fixed XSS on search


  Commit: 21f624a26574fd45c043ddd27bf5a190b80c2757
      https://github.com/phpmyadmin/phpmyadmin/commit/21f624a26574fd45c043ddd27bf5a190b80c2757
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-11-26 (Fri, 26 Nov 2010)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  ChangeLog for XSS search


  Commit: 3756112c7fbb243a954e96e762e1122b80b71dc4
      https://github.com/phpmyadmin/phpmyadmin/commit/3756112c7fbb243a954e96e762e1122b80b71dc4
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2010-11-26 (Fri, 26 Nov 2010)

  Changed paths:
    M libraries/common.lib.php

  Log Message:
  -----------
  bug #3115519: fixed XSS on search


  Commit: 68213538d7b53e3c97b8730a2e6a0e897b8b5ce9
      https://github.com/phpmyadmin/phpmyadmin/commit/68213538d7b53e3c97b8730a2e6a0e897b8b5ce9
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-11-26 (Fri, 26 Nov 2010)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  fix merge conflicts


  Commit: a6e79391b92a48ffef307fa107ce1a61965e4244
      https://github.com/phpmyadmin/phpmyadmin/commit/a6e79391b92a48ffef307fa107ce1a61965e4244
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-11-26 (Fri, 26 Nov 2010)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11.1 release


  Commit: 61d9e561580ccb4a07d6d0c5695c839a22cc3b78
      https://github.com/phpmyadmin/phpmyadmin/commit/61d9e561580ccb4a07d6d0c5695c839a22cc3b78
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2010-11-29 (Mon, 29 Nov 2010)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  2.11.11.1 release date and PMASA ref


  Commit: b01a58118f973f98ab99a4bb28d340af49fa251f
      https://github.com/phpmyadmin/phpmyadmin/commit/b01a58118f973f98ab99a4bb28d340af49fa251f
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-01-06 (Thu, 06 Jan 2011)

  Changed paths:
    R error.php
  M libraries/common.inc.php
  M libraries/core.lib.php
  A libraries/error.inc.php

  Log Message:
  -----------
  Remove error.php

Redirecting to other script introduces possibility of inject custom
messages to it. Though there is no clear security issue in this, it
might confuse users and mistake them to go to external site as it allows
to include links.

Conflicts:

	error.php
	libraries/core.lib.php


  Commit: 3f9fd2594076bd8ee0825b59f7caf55be102ce4f
      https://github.com/phpmyadmin/phpmyadmin/commit/3f9fd2594076bd8ee0825b59f7caf55be102ce4f
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-01-06 (Thu, 06 Jan 2011)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  Merge remote branch 'origin/MAINT_2_11_11' into QA_2_11


  Commit: 60bdae640377ed32c717e6f863b77359f04a7bb5
      https://github.com/phpmyadmin/phpmyadmin/commit/60bdae640377ed32c717e6f863b77359f04a7bb5
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-01-06 (Thu, 06 Jan 2011)

  Changed paths:
    A .gitignore
  A themes/.gitignore

  Log Message:
  -----------
  Add .gitignore from master.


  Commit: 373a6626ade37c0fee1dfc7c757ca55c7652874b
      https://github.com/phpmyadmin/phpmyadmin/commit/373a6626ade37c0fee1dfc7c757ca55c7652874b
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-01-06 (Thu, 06 Jan 2011)

  Changed paths:
    M phpinfo.php

  Log Message:
  -----------
  Do not load common with PMA_MINIMUM_COMMON

Defining PMA_MINIMUM_COMMON skips authentication, what should not be
done for this file.


  Commit: 87fad589653478875ba6f86a5c5ceec805d0f8b2
      https://github.com/phpmyadmin/phpmyadmin/commit/87fad589653478875ba6f86a5c5ceec805d0f8b2
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2011-02-08 (Tue, 08 Feb 2011)

  Changed paths:
    M changelog.php
  M license.php
  M readme.php

  Log Message:
  -----------
  PMASA-2011-1 fixes


  Commit: 448940b37b55648248d9a62139b8838feece3931
      https://github.com/phpmyadmin/phpmyadmin/commit/448940b37b55648248d9a62139b8838feece3931
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-08 (Tue, 08 Feb 2011)

  Changed paths:
    M ChangeLog
  M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11.2 release


  Commit: f0e8849034132e2114f1d77d9d37185bc5b49886
      https://github.com/phpmyadmin/phpmyadmin/commit/f0e8849034132e2114f1d77d9d37185bc5b49886
  Author: Herman van Rink <rink at initfour.nl>
  Date:   2011-02-08 (Tue, 08 Feb 2011)

  Changed paths:
    M changelog.php
  M license.php
  M readme.php

  Log Message:
  -----------
  PMASA-2011-1 fixes


  Commit: d620aaf102e9a9f850cc3a5cd77ff6de40dda782
      https://github.com/phpmyadmin/phpmyadmin/commit/d620aaf102e9a9f850cc3a5cd77ff6de40dda782
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-08 (Tue, 08 Feb 2011)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  ChangeLog for 2.11.11.2


  Commit: 79a4e4b7feff498e422267d91f071a4b92690282
      https://github.com/phpmyadmin/phpmyadmin/commit/79a4e4b7feff498e422267d91f071a4b92690282
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-08 (Tue, 08 Feb 2011)

  Log Message:
  -----------
  Merge remote branch 'origin/MAINT_2_11_11' into QA_2_11


  Commit: 2fa4c8d97a92ae0d4e2051d5d18a18688c31f84f
      https://github.com/phpmyadmin/phpmyadmin/commit/2fa4c8d97a92ae0d4e2051d5d18a18688c31f84f
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M libraries/bookmark.lib.php
  M sql.php

  Log Message:
  -----------
  Avoid using all users query as default when browsing.


  Commit: 6488ee49ab3889e8d364d6a778a6c6b7ffe15dbe
      https://github.com/phpmyadmin/phpmyadmin/commit/6488ee49ab3889e8d364d6a778a6c6b7ffe15dbe
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M libraries/bookmark.lib.php
  M sql.php

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_11' into QA_2_11


  Commit: dd60d67d23d9906473369c4a05c489be3ee4cd5d
      https://github.com/phpmyadmin/phpmyadmin/commit/dd60d67d23d9906473369c4a05c489be3ee4cd5d
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M import.php

  Log Message:
  -----------
  Force bookmark ID to be integer


  Commit: fffee916bbed69dfc7b7cd9e7ef7ed4ea1333883
      https://github.com/phpmyadmin/phpmyadmin/commit/fffee916bbed69dfc7b7cd9e7ef7ed4ea1333883
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M import.php

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_11' into QA_2_11


  Commit: cc02c4a58b455614fca9279053a0eaf1e178c987
      https://github.com/phpmyadmin/phpmyadmin/commit/cc02c4a58b455614fca9279053a0eaf1e178c987
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  2.11.11.3 ChangeLog


  Commit: 715ba42d942abccc7e49ca8e4fb21064693eadf8
      https://github.com/phpmyadmin/phpmyadmin/commit/715ba42d942abccc7e49ca8e4fb21064693eadf8
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  2.11.11.3 ChangeLog


  Commit: 92ba791007bcdef903b8ceaa1bb3d3b3f952036c
      https://github.com/phpmyadmin/phpmyadmin/commit/92ba791007bcdef903b8ceaa1bb3d3b3f952036c
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-11 (Fri, 11 Feb 2011)

  Changed paths:
    M Documentation.html
  M README
  M libraries/Config.class.php
  M translators.html

  Log Message:
  -----------
  2.11.11.3 release


  Commit: 3b6d78aef06c93fcf44730cff44666916cb702bb
      https://github.com/phpmyadmin/phpmyadmin/commit/3b6d78aef06c93fcf44730cff44666916cb702bb
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2011-02-12 (Sat, 12 Feb 2011)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  Reference to minor security fixes


  Commit: cd147951afdf9fdb1ab47625eac9fa739e673240
      https://github.com/phpmyadmin/phpmyadmin/commit/cd147951afdf9fdb1ab47625eac9fa739e673240
  Author: Michal Čihař <mcihar at novell.com>
  Date:   2011-02-14 (Mon, 14 Feb 2011)

  Log Message:
  -----------
  Merge branch 'MAINT_2_11_11' into QA_2_11


  Commit: 977ec6f8e210fd305049a6d081a9426b882e3199
      https://github.com/phpmyadmin/phpmyadmin/commit/977ec6f8e210fd305049a6d081a9426b882e3199
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge remote-tracking branches 'origin/MAINT_2_10_0', 'origin/MAINT_2_10_2' and 'origin/MAINT_2_10_3' into QA_2_10


  Commit: 828d01d2035e154227e117f268b10b259590949c
      https://github.com/phpmyadmin/phpmyadmin/commit/828d01d2035e154227e117f268b10b259590949c
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge remote-tracking branches 'origin/MAINT_2_11_0', 'origin/MAINT_2_11_1', 'origin/MAINT_2_11_10', 'origin/MAINT_2_11_11', 'origin/MAINT_2_11_2', 'origin/MAINT_2_11_3', 'origin/MAINT_2_11_4', 'origin/MAINT_2_11_5', 'origin/MAINT_2_11_6', 'origin/MAINT_2_11_7', 'origin/MAINT_2_11_8' and 'origin/MAINT_2_11_9' into QA_2_11


  Commit: 62306d3e6a4934b13e499d037d5c029a033921d9
      https://github.com/phpmyadmin/phpmyadmin/commit/62306d3e6a4934b13e499d037d5c029a033921d9
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge remote-tracking branches 'origin/MAINT_2_9_0', 'origin/MAINT_2_9_1' and 'origin/MAINT_2_9_2' into QA_2_9


  Commit: d972e71e0a952605487ced7d08f4b2e10cf4cd63
      https://github.com/phpmyadmin/phpmyadmin/commit/d972e71e0a952605487ced7d08f4b2e10cf4cd63
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge remote-tracking branches 'origin/MAINT_3_0_0' and 'origin/MAINT_3_0_1' into QA_3_0


  Commit: b09cad4342de52e0fba71838d92245f766773230
      https://github.com/phpmyadmin/phpmyadmin/commit/b09cad4342de52e0fba71838d92245f766773230
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge branch 'QA_2_9' into QA_2_10


  Commit: fa27f371f4a3667e4b7d27f381bc0bbacccc34a0
      https://github.com/phpmyadmin/phpmyadmin/commit/fa27f371f4a3667e4b7d27f381bc0bbacccc34a0
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge branch 'QA_2_10' into QA_2_11


  Commit: 8a7cf503a3fe93f44e6c2092d769aeaa275d693c
      https://github.com/phpmyadmin/phpmyadmin/commit/8a7cf503a3fe93f44e6c2092d769aeaa275d693c
  Author: Michal Čihař <mcihar at suse.cz>
  Date:   2012-04-11 (Wed, 11 Apr 2012)

  Log Message:
  -----------
  Merge branch 'QA_2_11' into QA_3_0


Compare: https://github.com/phpmyadmin/phpmyadmin/compare/5b781c4...8a7cf50


More information about the Git mailing list