[Phpmyadmin-git] [phpmyadmin/phpmyadmin] daa98d: Fix XSS in Hide navigation items feature

Marc Delisle marc at infomarc.info
Sun Aug 17 19:17:52 CEST 2014


  Branch: refs/heads/STABLE
  Home:   https://github.com/phpmyadmin/phpmyadmin
  Commit: daa98d0c7ed24b529dc5df0d5905873acd0b00be
      https://github.com/phpmyadmin/phpmyadmin/commit/daa98d0c7ed24b529dc5df0d5905873acd0b00be
  Author: Ann + J.M <phpMyAdmin at ZweiSteinSoft.de>
  Date:   2014-06-21 (Sat, 21 Jun 2014)

  Changed paths:
    M libraries/navigation/Navigation.class.php
    M libraries/navigation/Nodes/Node_DatabaseChild.class.php

  Log Message:
  -----------
  Fix XSS in Hide navigation items feature

Signed-off-by: Ann + J.M <phpMyAdmin at ZweiSteinSoft.de>


  Commit: d143c549f92f4d5eeec50ba0d21b301e466c0d95
      https://github.com/phpmyadmin/phpmyadmin/commit/d143c549f92f4d5eeec50ba0d21b301e466c0d95
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-06-21 (Sat, 21 Jun 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.1.14.1 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 45550b8cff06ad128129020762f9b53d125a6934
      https://github.com/phpmyadmin/phpmyadmin/commit/45550b8cff06ad128129020762f9b53d125a6934
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-15 (Tue, 15 Jul 2014)

  Changed paths:
    M ChangeLog
    M server_user_groups.php

  Log Message:
  -----------
  bug #4491 [security] Missing validation for accessing User groups feature

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 1b5592435617fa1b9dd68e2dc263de64c69fdc8a
      https://github.com/phpmyadmin/phpmyadmin/commit/1b5592435617fa1b9dd68e2dc263de64c69fdc8a
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M ChangeLog
    M libraries/rte/rte_list.lib.php

  Log Message:
  -----------
  bug #4488 [security] XSS injection due to unescaped table name (triggers)

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 511c596b175889b8e6b9c423e352ca64fa20af2b
      https://github.com/phpmyadmin/phpmyadmin/commit/511c596b175889b8e6b9c423e352ca64fa20af2b
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M ChangeLog
    M libraries/rte/rte_list.lib.php

  Log Message:
  -----------
  bug #4488 [security] XSS injection due to unescaped table name (triggers)

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: a92753bd65e1f8b72c46ed3dda6c362628e0daf7
      https://github.com/phpmyadmin/phpmyadmin/commit/a92753bd65e1f8b72c46ed3dda6c362628e0daf7
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js
    M js/tbl_structure.js

  Log Message:
  -----------
  bug #4492 [security] XSS in AJAX confirmation messages

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: cd5697027a2ee7e1f7d7000b23be6051cdb0516c
      https://github.com/phpmyadmin/phpmyadmin/commit/cd5697027a2ee7e1f7d7000b23be6051cdb0516c
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js
    M js/tbl_structure.js

  Log Message:
  -----------
  bug #4492 [security] XSS in AJAX confirmation messages

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 2a211a595f6eb54db3d842ee23b6ff22ac608a14
      https://github.com/phpmyadmin/phpmyadmin/commit/2a211a595f6eb54db3d842ee23b6ff22ac608a14
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M ChangeLog
    M server_user_groups.php

  Log Message:
  -----------
  Fix merge conflict

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: f86761326c97eb5e2c9cefa2b1871252357f00a0
      https://github.com/phpmyadmin/phpmyadmin/commit/f86761326c97eb5e2c9cefa2b1871252357f00a0
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.0.10.1 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 0f781c803cf70b386736f079b883695fec08cfcb
      https://github.com/phpmyadmin/phpmyadmin/commit/0f781c803cf70b386736f079b883695fec08cfcb
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-07-17 (Thu, 17 Jul 2014)

  Changed paths:
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.1.14.2 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 285ed5b8d3bc9279fe6ed01da8151ed66be9b137
      https://github.com/phpmyadmin/phpmyadmin/commit/285ed5b8d3bc9279fe6ed01da8151ed66be9b137
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/sql.js

  Log Message:
  -----------
  bug #4501 [security] XSS in table browse page


  Commit: 0433d463b6c05ea7b1080995414268fe0a449b00
      https://github.com/phpmyadmin/phpmyadmin/commit/0433d463b6c05ea7b1080995414268fe0a449b00
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js

  Log Message:
  -----------
  bug #4502 [security] Self-XSS in enum value editor

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 3668255202062dd7d60bff70236302084e73fc11
      https://github.com/phpmyadmin/phpmyadmin/commit/3668255202062dd7d60bff70236302084e73fc11
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/server_status_monitor.js

  Log Message:
  -----------
  bug #4503 [security] Self-XSSes in monitor

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 03b92aa6e923f2b4a54b298cc0042548ff7ba89b
      https://github.com/phpmyadmin/phpmyadmin/commit/03b92aa6e923f2b4a54b298cc0042548ff7ba89b
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/tbl_chart.js

  Log Message:
  -----------
  bug #4504 [security] Self-XSS in query charts

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 5cd9839467588b7882a5d28452d318a6caaf6b18
      https://github.com/phpmyadmin/phpmyadmin/commit/5cd9839467588b7882a5d28452d318a6caaf6b18
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog

  Log Message:
  -----------
  Fix typo

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 65eef3d65411b985250487e14f1121754a91c6d5
      https://github.com/phpmyadmin/phpmyadmin/commit/65eef3d65411b985250487e14f1121754a91c6d5
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-06 (Wed, 06 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js

  Log Message:
  -----------
  bug #4505 [security] XSS in view operations page

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 098caf93b63d4928e4df53310222c8727d0be9fe
      https://github.com/phpmyadmin/phpmyadmin/commit/098caf93b63d4928e4df53310222c8727d0be9fe
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-16 (Sat, 16 Aug 2014)

  Changed paths:
    M ChangeLog
    M tbl_relation.php

  Log Message:
  -----------
  bug #4517 [security] XSS in relation view

Signed-off-by: Madhura Jayaratne <madhura.cj at gmail.com>


  Commit: 5e5261284190c6fe6985547fbd19d3345df14be1
      https://github.com/phpmyadmin/phpmyadmin/commit/5e5261284190c6fe6985547fbd19d3345df14be1
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.0.10.2 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 7299fcd8d1561b8056afc919e0a719e3b2da7acc
      https://github.com/phpmyadmin/phpmyadmin/commit/7299fcd8d1561b8056afc919e0a719e3b2da7acc
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M js/functions.js
    M js/server_status_monitor.js
    M js/sql.js
    M js/tbl_chart.js
    M libraries/Config.class.php
    M tbl_relation.php

  Log Message:
  -----------
  Merge branch 'MAINT_4_0_10' into STABLE


  Commit: 2d394521197f81dce0d9529b2d86ed24760b5b2a
      https://github.com/phpmyadmin/phpmyadmin/commit/2d394521197f81dce0d9529b2d86ed24760b5b2a
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/sql.js

  Log Message:
  -----------
  bug #4501 [security] XSS in table browse page

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 1956420ddab0595016ba2b3af89f7f82d39f5afa
      https://github.com/phpmyadmin/phpmyadmin/commit/1956420ddab0595016ba2b3af89f7f82d39f5afa
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js

  Log Message:
  -----------
  bug #4502 [security] Self-XSS in enum value editor

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 69f746b7dc09f7b1a18b09de0b5cd71f0bcd0a3d
      https://github.com/phpmyadmin/phpmyadmin/commit/69f746b7dc09f7b1a18b09de0b5cd71f0bcd0a3d
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/server_status_monitor.js

  Log Message:
  -----------
  bug #4503 [security] Self-XSSes in monitor

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: bbd20b54864a389c7a0cd2c4d4715f00b81a03e9
      https://github.com/phpmyadmin/phpmyadmin/commit/bbd20b54864a389c7a0cd2c4d4715f00b81a03e9
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/tbl_chart.js

  Log Message:
  -----------
  bug #4504 [security] Self-XSS in query charts

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 5519905a2519d9a102b172432448c7e91d5601a6
      https://github.com/phpmyadmin/phpmyadmin/commit/5519905a2519d9a102b172432448c7e91d5601a6
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M libraries/tbl_relation.lib.php

  Log Message:
  -----------
  bug #4517 [security] XSS in relation view

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 54d738568bac627afdb3b7dad22787fcc17956e9
      https://github.com/phpmyadmin/phpmyadmin/commit/54d738568bac627afdb3b7dad22787fcc17956e9
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.1.14.3 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: f6c684fc6701a9a6ae754efb9602ca1ab61b1185
      https://github.com/phpmyadmin/phpmyadmin/commit/f6c684fc6701a9a6ae754efb9602ca1ab61b1185
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M js/functions.js
    M js/sql.js
    M js/tbl_chart.js
    M libraries/Config.class.php
    M libraries/tbl_relation.lib.php

  Log Message:
  -----------
  Merge branch 'MAINT_4_1_14' into STABLE


  Commit: 0cd293f5e13aa245e4a57b8d373597cc0e421b6f
      https://github.com/phpmyadmin/phpmyadmin/commit/0cd293f5e13aa245e4a57b8d373597cc0e421b6f
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js

  Log Message:
  -----------
  bug #4505 [security] XSS in view operations page

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 647c9d12e33a6b64e1c3ff7487f72696bdf2dccb
      https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccb
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/sql.js

  Log Message:
  -----------
  bug #4501 [security] XSS in table browse page

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 2c45d7caa614afd71dbe3d0f7270f51ce5569614
      https://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/functions.js

  Log Message:
  -----------
  bug #4502 [security] Self-XSS in enum value editor

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: cd9f302bf7f91a160fe7080f9a612019ef847f1c
      https://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/server_status_monitor.js

  Log Message:
  -----------
  bug #4503 [security] Self-XSSes in monitor

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 90ddeecf60fc029608b972e490b735f3a65ed0cb
      https://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cb
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M js/tbl_chart.js

  Log Message:
  -----------
  bug #4504 [security] Self-XSS in query charts

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 3ffc967fb60cf2910cc2f571017e977558c67821
      https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821
  Author: Madhura Jayaratne <madhura.cj at gmail.com>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M libraries/tbl_relation.lib.php

  Log Message:
  -----------
  bug #4517 [security] XSS in relation view

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 7f977f46335b9707fb5f7bf30d6bdb92263d2233
      https://github.com/phpmyadmin/phpmyadmin/commit/7f977f46335b9707fb5f7bf30d6bdb92263d2233
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  4.2.7.1 release

Signed-off-by: Marc Delisle <marc at infomarc.info>


  Commit: 2c87e5df39c04199b7b285e7c1e7fda695b34614
      https://github.com/phpmyadmin/phpmyadmin/commit/2c87e5df39c04199b7b285e7c1e7fda695b34614
  Author: Marc Delisle <marc at infomarc.info>
  Date:   2014-08-17 (Sun, 17 Aug 2014)

  Changed paths:
    M ChangeLog
    M README
    M doc/conf.py
    M libraries/Config.class.php

  Log Message:
  -----------
  Merge branch 'MAINT_4_2_7' into STABLE


Compare: https://github.com/phpmyadmin/phpmyadmin/compare/0d551ceab557...2c87e5df39c0


More information about the Git mailing list