Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-10611

Add a check for selected tables existence for ACP database backup tool

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 3.0.10
    • Fix Version/s: 3.0.11-RC1
    • Component/s: ACP
    • Labels:
      None

      Description

      In includes/acp/acp_database.php there's no check for existence of the tables selected to backup.
      This may cause unwanted use of HTML page source to handle table names list, which may cause errors or harmful queries injection into the dump.

        Attachments

          Activity

            People

            • Assignee:
              bantu Andreas Fischer
              Reporter:
              rxu rxu
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: