aboutsummaryrefslogtreecommitdiffstats
path: root/main/phpmyadmin/CVE-2014-1879.patch
blob: beb12d75429ad166413835e6f5e7e0df194509f2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
--- ./import.php.orig
+++ ./import.php
@@ -409,11 +409,11 @@
             $message->addParam($executed_queries);
 
             $message->addString($import_notice);
-            $message->addString('(' . $_FILES['import_file']['name'] . ')');
+            $message->addString('(' . htmlspecialchars($_FILES['import_file']['name']) . ')');
         } else {
             $message = PMA_Message::success(__('Import has been successfully finished, %d queries executed.'));
             $message->addParam($executed_queries);
-            $message->addString('(' . $_FILES['import_file']['name'] . ')');
+            $message->addString('(' . htmlspecialchars($_FILES['import_file']['name']) . ')');
         }
     }
 }