summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--meta-webserver/recipes-php/phpmyadmin/phpmyadmin/0001-bug-4504-security-Self-XSS-in-query-charts.patch29
-rw-r--r--meta-webserver/recipes-php/phpmyadmin/phpmyadmin_4.2.7.bb1
2 files changed, 30 insertions, 0 deletions
diff --git a/meta-webserver/recipes-php/phpmyadmin/phpmyadmin/0001-bug-4504-security-Self-XSS-in-query-charts.patch b/meta-webserver/recipes-php/phpmyadmin/phpmyadmin/0001-bug-4504-security-Self-XSS-in-query-charts.patch
new file mode 100644
index 0000000000..27eac77629
--- /dev/null
+++ b/meta-webserver/recipes-php/phpmyadmin/phpmyadmin/0001-bug-4504-security-Self-XSS-in-query-charts.patch
@@ -0,0 +1,29 @@
1From 90ddeecf60fc029608b972e490b735f3a65ed0cb Mon Sep 17 00:00:00 2001
2From: Madhura Jayaratne <madhura.cj@gmail.com>
3Date: Sun, 17 Aug 2014 08:52:05 -0400
4Subject: [PATCH] bug #4504 [security] Self-XSS in query charts
5
6Upstream-status: Backport
7
8Signed-off-by: Marc Delisle <marc@infomarc.info>
9---
10 js/tbl_chart.js | 2 +-
11 2 files changed, 2 insertions(+), 1 deletion(-)
12
13 4.2.7.0 (2014-07-31)
14diff --git a/js/tbl_chart.js b/js/tbl_chart.js
15index 943d4ae..04c9c40 100644
16--- a/js/tbl_chart.js
17+++ b/js/tbl_chart.js
18@@ -47,7 +47,7 @@ function PMA_queryChart(data, columnNames, settings) {
19 },
20 axes : {
21 xaxis : {
22- label : settings.xaxisLabel
23+ label : escapeHtml(settings.xaxisLabel)
24 },
25 yaxis : {
26 label : settings.yaxisLabel
27--
281.7.10.4
29
diff --git a/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_4.2.7.bb b/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_4.2.7.bb
index 0de3f6d43c..c267d89621 100644
--- a/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_4.2.7.bb
+++ b/meta-webserver/recipes-php/phpmyadmin/phpmyadmin_4.2.7.bb
@@ -6,6 +6,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=eb723b61539feef013de476e68b5c50a \
6 file://libraries/tcpdf/LICENSE.TXT;md5=5c87b66a5358ebcc495b03e0afcd342c" 6 file://libraries/tcpdf/LICENSE.TXT;md5=5c87b66a5358ebcc495b03e0afcd342c"
7 7
8SRC_URI = "${SOURCEFORGE_MIRROR}/phpmyadmin/phpMyAdmin/${PV}/phpMyAdmin-${PV}-all-languages.tar.xz \ 8SRC_URI = "${SOURCEFORGE_MIRROR}/phpmyadmin/phpMyAdmin/${PV}/phpMyAdmin-${PV}-all-languages.tar.xz \
9 file://0001-bug-4504-security-Self-XSS-in-query-charts.patch \
9 file://apache.conf" 10 file://apache.conf"
10 11
11SRC_URI[md5sum] = "0dcd755450dac819f33502590c88ad29" 12SRC_URI[md5sum] = "0dcd755450dac819f33502590c88ad29"