From 2e1d5ac20a6245d50fcf09f4ba90eb6b7197a360 Mon Sep 17 00:00:00 2001 From: Marc Delisle Date: Wed, 24 Aug 2011 12:39:43 -0400 Subject: [PATCH] ChangeLog and 3.4.4 XSS fix --- ChangeLog | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 85e45ab7e8..680d3fa3db 100644 --- a/ChangeLog +++ b/ChangeLog @@ -59,7 +59,7 @@ phpMyAdmin - ChangeLog - [import] Remove native Excel import modules (xls and xlsx formats) - bug #3392920 [edit] BLOB emptied after editing another column -3.4.4.0 (not yet released) +3.4.4.0 (2011-08-24) - bug #3323060 [parser] SQL parser breaks AJAX requests if query has unclosed quotes - bug #3323101 [parser] Invalid escape sequence in SQL parser - bug #3348995 [config] $cfg['Export']['asfile'] set to false does not select asText option @@ -77,6 +77,7 @@ phpMyAdmin - ChangeLog - bug #3372807 [interface] Fix security warning link in setup - bug #3374347 [display] Backquotes in normal text on import page - bug #3358750 [core] With Suhosin, urls are too long in edit links +- [security] Missing sanitization on the table, column and index names leads to XSS vulnerabilities, see PMASA-2011-13 3.4.3.2 (2011-07-23) - [security] Fixed XSS vulnerability, see PMASA-2011-9 -- 2.11.4.GIT