Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/phpmyadmin/phpmyadmin.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMadhura Jayaratne <madhura.cj@gmail.com>2016-02-29 03:12:07 +0300
committerMadhura Jayaratne <madhura.cj@gmail.com>2016-02-29 03:12:07 +0300
commitcc55f44a4a90147a007dee1aefa1cb529e23798b (patch)
tree09d23b3227a481b7c5e1c169f25680096d104f77 /db_central_columns.php
parentab1283e8366c97a155d4e9ae58628a248458ea32 (diff)
Fix XSS in Central columns page
Signed-off-by: Madhura Jayaratne <madhura.cj@gmail.com>
Diffstat (limited to 'db_central_columns.php')
-rw-r--r--db_central_columns.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/db_central_columns.php b/db_central_columns.php
index 2e9aac73bb..4c78eba255 100644
--- a/db_central_columns.php
+++ b/db_central_columns.php
@@ -92,7 +92,7 @@ if (isset($_REQUEST['total_rows']) && $_REQUEST['total_rows']) {
} else {
$total_rows = PMA_getCentralColumnsCount($db);
}
-if (isset($_REQUEST['pos'])) {
+if (PMA_isValid($_REQUEST['pos'], 'integer')) {
$pos = $_REQUEST['pos'];
} else {
$pos = 0;