aboutsummaryrefslogtreecommitdiffstats
path: root/main/phpmyadmin/CVE-2014-1879.patch
blob: 4176824602c7f26935034c6d06db1c4282b0de67 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
--- ./import.php.orig
+++ ./import.php
@@ -549,9 +549,9 @@
 
             $message->addString($import_notice);
             if (isset($local_import_file)) {
-                $message->addString('(' . $local_import_file . ')');
+                $message->addString('(' . htmlspecialchars($local_import_file) . ')');
             } else {
-                $message->addString('(' . $_FILES['import_file']['name'] . ')');
+                $message->addString('(' . htmlspecialchars($_FILES['import_file']['name']) . ')');
             }
         } else {
             $message = PMA_Message::success(