diff --git a/htdocs/sql/ChangeLog b/htdocs/sql/ChangeLog new file mode 100755 --- /dev/null +++ b/htdocs/sql/ChangeLog @@ -0,0 +1,635 @@ +---------------------- +phpMyAdmin - ChangeLog +---------------------- + +$Id: ChangeLog 12317 2009-03-24 21:04:18Z lem9 $ +$HeadURL: https://phpmyadmin.svn.sourceforge.net/svnroot/phpmyadmin/trunk/phpMyAdmin/ChangeLog $ + +2.11.9.5 (2009-03-24) +- [security] XSS vulnerability on export page +- [security] Insufficient output sanitizing when generating configuration file + +2.11.9.4 (2008-12-09) +- [security] possible XSRF on several pages + +2.11.9.3 (2008-10-30) +- [security] XSS in a Designer component + +2.11.9.2 (2008-09-22) +- [security] XSS in MSIE using NUL byte, thanks to JPCERT. + +2.11.9.1 (2008-09-15) +- [security] Code execution vulnerability, thanks to Norman Hippert + +2.11.9.0 (2008-08-28) +- bug #2031221 [auth] Links to version number on login screen +- bug #2032707 [core] PMA does not start if ini_set() is disabled +- bug #2004915 [bookmarks] Saved queries greater than 1000 chars not + displayed, thanks to Maik Wiege - mswiege +- bug #2037381 [export] Export type "replace" does not work +- bug #2037375 [export] DROP PROCEDURE needs IF EXISTS +- bug #2045512 [export] Numbers in Excel export ++ [lang] Norwegian UTF-8 original file remerged, thanks to Sven-Erik Andersen +- bug #2074250 [parser] Undefined variable seen_from + +2.11.8.0 (2008-07-28) +- patch #1987593 [interface] Table list pagination in navi, + thanks to Jason Day - jday29 +- bug #1989081 [profiling] Profiling causes query to be executed again + (really causes a problem in case of INSERT/UPDATE) +- bug #1990342 [import] SQL file import very slow on Windows, + thanks to Richard Heaton - wotnot +- bug [XHTML] problem with tabindex and radio fields +- bug #1971221 [interface] tabindex not set correctly +- bug [views] VIEW name created via the GUI was not protected with backquotes +- bug #1989813 [interface] Deleting multiple views (space in name) +- bug #1992628 [parser] SQL parser removes essential space +- bug #1989281 [export] CSV for MS Excel incorrect escaping of double quotes +- bug #1959855 [interface] Font size option problem when no config file +- bug #1982489 [relation] Relationship view should check for changes +- bug [history] Do not save too big queries in history +- [security] Do not show version info on login screen +- bug #2018595 [import] Potential data loss on import resubmit +- patch #2020630 [export] Safari and timedate, thanks to Sebastian Mendel, + Isaac Bennetch and Jürgen Wind +- bug #2022182 [import, export] Import/Export fails because of Mac files +- [security] protection against cross-frame scripting and + new directive AllowThirdPartyFraming, thanks to YGN Ethical Hacker Group +- [security] possible XSS during setup, thanks to YGN Ethical Hacker Group +- [interface] revert language changing problem introduced with 2.11.7.1 + +2.11.7.1 (2008-07-15) +- bug [security] XSRF/CSRF by manipulating the db, + convcharset and collation_connection parameters, + thanks to YGN Ethical Hacker Group + +2.11.7.0 (2008-06-23) +- bug #1908719 [interface] New field cannot be auto-increment and primary key +- [dbi] Incorrect interpretation for some mysqli field flags +- bug #1910621 [display] part 1: do not display a TEXT utf8_bin as BLOB + (fixed for mysqli extension only) +- [interface] sanitize the after_field parameter, + thanks to Norman Hippert +- [structure] do not remove the BINARY attribute in drop-down +- bug #1955386 [session] Overriding session.hash_bits_per_character +- [interface] sanitize the table comments in table print view, + db print view and db data dictionary, thanks to Norman Hippert +- bug #1939031 Auto_Increment selected for TimeStamp by Default +- patch #1957998 [display] No tilde for InnoDB row counter when we know + it for sure, thanks to Vladyslav Bakayev - dandy76 +- bug #1955572 [display] alt text causes duplicated strings +- bug #1762029 [interface] Cannot upload BLOB into existing row +- bug #1981043 [export] HTML in exports getting corrupted, + thanks to Jason Judge - jasonjudge +- bug #1936761 [interface] BINARY not treated as BLOB: update/delete issues +- protection against XSS when register_globals is on and .htaccess has + no effect, thanks to Tim Starling +- bug #1996943 [export] Firefox 3 and .sql.gz (corrupted); detect Gecko 1.9, + thanks to Jürgen Wind - windkiel + +2.11.6.0 (2008-04-29) +- bug #1903724 [interface] Displaying of very large queries in error message +- bug #1905711 [compatibility] Functions deprecated in PHP 5.3: is_a() and + get_magic_quotes_gpc(), thanks to Dmitry N. Shilnikov - yrtimd +- bug [lang] catalan wrong accented characters +- bug #1893034 [Export] SET NAMES for importing with command-line client ++ [lang] Russian update, thanks to Victor Volkov +- bug #1910485 [core] Unsetting the whitelist during the loop, + thanks to Jeroen Vrijkorte - jv_map +- bug #1906980 [Export] Import of VIEWs fails if temp table exists, + thanks to Falk Nisius - klaf +- bug #1812763 [Copy] Table copy when server is in ANSI_QUOTES sql_mode + thanks to Tony Marston - tonymarston +- bug #1918531 [compatibility] Navigation isn't w3.org valid + thanks to Michael Keck - mkkeck +- bug #1926357 [data] BIT defaults displayed incorrectly +- patch #1930057 [auth] colon in password prevents HTTP login on CGI/IIS, + thanks to Jürgen Wind - windkiel +- patch #1929553 [lang] Don't output BOM character in Swedish language file, + thanks to Samuel L. B. - samuellb +- patch #1895796 [lang] Typo in Japanese lang files, + thanks to tyman - acoustype +- bug #1935652 [auth] Access denied (show warning about mcrypt on login page) +- bug #1906983 [export] Reimport of FUNCTION fails +- bug #1919808 [operations] Renaming a database fails to handle functions +- bug #1934401 [core] Cannot force a language +- bug #1944077 [core] Config file containing a BOM, + thanks to Gaetano Giunta - ggiunta +- bug #1947189 [scripts] Missing in scripts/signon.php, + thanks to Dolf Schimmel ++ [lang] Romanian update, thanks to Sergiu Bivol - sbivol + +2.11.5.2 (2008-04-22) +- PMASA-2008-3 [security] File disclosure + +2.11.5.1 (2008-03-29) +- bug #1909711 [security] Sensitive data in session files + +2.11.5.0 (2008-03-01) +- bug #1862661 [GUI] Warn about rename deleting database +- bug #1866041 [interface] Incorrect sorting with AS +- bug #1871038 [import] Notice: undefined variable first_sql_delimiter +- bug #1873110 [export] Problem exporting with a LIMIT clause +- bug #1871164 [GUI] Empty and navigation frame synch. +- patch #1873188 [GUI] Making db pager work when js is disabled, + thanks to Jürgen Wind - windkiel +- bug #1875010 [auth] MySQL server and client version mismatch (mysql ext.) +- patch #1879031 [transform] dateformat transformation and UNIX timestamps, + thanks to Tim Steiner - spam38 +- bug [import] Do not verify a missing enclosing character for CSV, + because files generated by Excel don't have any enclosing character +- bug #1799691 [export] "Propose table structure" and Export +- bug #1884911 [GUI] Space usage +- bug #1863326 [GUI] Wrong error message / no edit (Suhosin) +- bug #1887204 [GUI] Order columns in result list messing up query +- patch #1893538 [GUI] Display issues on Opera 9.50, + thanks to Jürgen Wind - windkiel +- bug [GUI] Do not display the database name used by the previous user, + thanks to Ronny Görner +- bug [security] Remove cookies from $_REQUEST for better coexistence with + other applications, thanks to Richard Cunningham. See PMASA-2008-1. + +2.11.4.0 (2008-01-12) +- bug #1843428 [GUI] Space issue with DROP/DELETE/ALTER TABLE +- bug #1807816 [search] regular expression search doesn't work with + backslashes +- bug #1843463 [GUI] DROP PROCEDURE does not show alert +- bug #1835904 [GUI] Back link after a SQL error forgets the query +- bug #1835654 [core] wrong escaping when using double quotes +- bug #1817612 [cookies] Wrong cookie path on IIS with PHP-CGI, + thanks to Carsten Wiedmann +- bug #1848889 [export] export trigger should use DROP TRIGGER IF EXISTS +- bug #1851833 [display] Sorting forgets an explicit LIMIT + (fix for sorting on column headers) +- bug #1764182 [cookies] Suhosin cookie encryption breaks phpMyAdmin +- bug #1798786 [import] Wrong error when a string contains semicolon +- bug #1813508 [login] Missing parameter: field after re-login +- bug #1710144 [parser] Space after COUNT breaks Export but not Query +- bug #1783620 [parser] Subquery results without "as" are ignored +- bug #1821264 [display] MaxTableList and INFORMATION_SCHEMA +- bug #1859460 [display] Operations and many databases +- bug #1814679 [display] Database selection pagination when switching servers +- patch #1861717 [export] CSV Escape character not exported right, + thanks to nicolasdigraf +- bug #1864468 [display] Theme does not switch to darkblue_orange +- bug #1847409 [security] Path disclosure on darkblue_orange/layout.inc.php, + thanks to Jürgen Wind - windkiel + +2.11.3.0 (2007-12-08) +- patch #1818389 to remove a notice (failed to flush buffer), thanks to + Bertrand +- patch #1821154, HTTP authentication: fix auth working with php/mod_fastcgi, + thanks to yarodin +- wrong default charset in case of broken session +- bug #1824506 [profiling] Profile command repeated on older MySQL servers +- bug #1825172 [export] Exporting and functions +- bug #1817224 [import] Incorrect detection of file_uploads in some cases, + thanks to Juergen Wind +- bug #1777249 [display] Do not underline links in left panel (in default +- bug #1826022 [privileges] unable to add user (MySQL 3.23) since PMA 2.11.2 +- bug #1823045 [import] Error importing file with lowercase "delimiter" +- bug #1828913 [structure] Can't set FULLTEXT index on CHAR column +- bug #1804081 [export] export on server doesn't obey AllowAnyWhereRecoding +- bug #1789988 [display] space before SHOW COLUMNS +- bug #1831646 [table creation] Error in CREATE TABLE with multiple primary + keys and AUTO_INCREMENT +- [display] Division by zero when showing all records (page selector) +- bug #1828265 [privileges] No weird characters in generated password +- bug #1759194 [import] open_basedir warning +- bug #1793948 [parser] ROW_FORMAT incorrectly parsed +- undefined PMA_MYSQL_INT_VERSION when no default server is set +- bug #1763343 [session] Behavior with session.auto_start enabled ++ [lang] Hungarian update, thanks to Mihály Mészáros ++ [lang] German update, thanks to Jürgen Wind - windkiel +- patch #1837691 [query window] js errors, thanks to Victor Volkov +- patch #1839052 [lang] catalan not in UTF-8, thanks to jaz001 +- patch #1838626 [GUI] Login interface broken on Konqueror, thanks to fhimpe + +2.11.2.2 (2007-11-20) +- bug #1835123 [security] fixed XSS vulnerability on login page, + thanks to Tim Brown (Nth Dimension) for the advisory + and to Sebastian for the fix + +2.11.2.1 (2007-11-11) +- fixed possible SQL injection using database name +- fixed possible XSS in database name - thanks to Omer Singer, The DigiTrust Group + +2.11.2.0 (2007-10-27) +- patch #1791576 HTTP auth: support REDIRECT_REMOTE_USER, thanks to Allard ++ [lang] Serbian update, thanks to Mihailo Stefanovic +- bug #1798841 [relations] Copying db does not copy internal relations +- bug #1798646 [display] Character '+' in query wrongly interpreted +- bug #1801919 [themes] Do not use NaviDatabaseNameColor for fieldset legend +- bug #1764735 [core] Designer: PDF error when deleting a table +- bug #1764195 [views] DROP button does not work on defective views +- bug #1805773 [relations] browse foreign values: return values not escaped, + thanks to Alex Rambau +- bug #1807923 [login] Login with html entities in password fails +- [core] Undefined variable when creating a table that exists +- patch #1808578 Changes in font size were no longer detected after patch + #1787915 ++ [lang] Croatian update, thanks to Renato Pavicic +- patch #1807615 [GUI] Display patch for column rights in Opera +- bug #1811519 Can't delete user with a german umlaut. +- bug #1811519 [privileges] fixed used collation for accessing mysql.user in server privileges +- it should not be possible to move or copy a table to information_schema +- bug #1814733 win: copy db to mixed name db fails +- bug #1777249 [display] Remove horizontal lines in navigation panel +- bug #1805102 [display] TextareaAutoSelect issues: set this parameter + default value to false to help cut&paste from a terminal window; also + set focus to the textarea +- bug #1814463 [display] Wrong database size +- bug #1811527 [display] Problem with links to the MySQL manual +- patch #1817529 [auth] Incorrect login via URL when AllowArbitraryServer + is true, thanks to Juergen Wind + +2.11.1.2 (2007-10-17) +- fixed XSS in server_status.php, thanks to Omer Singer, The DigiTrust Group +- fixed some possible XSS with PHP_SELF, PATH_INFO, REQUEST_URI + (reference: CVE-2007-5589) + +2.11.1.1 (2007-10-15) +- bug #1810629 [setup] XSS in setup.php, thanks to Omer Singer, The DigiTrust Group + +2.11.1.0 (2007-09-20) +- bug #1783667 [export] NO_AUTO_VALUE_ON_ZERO and MySQL version +- bug #1780098 [GUI] Logout causes CSS loss, thanks to Juergen Wind +. incorrect field ids, thanks to Michael Keck +- bug #1787522 [view] wrong choice in algorithm drop-down +- bug #1777620 [GUI] Table Print preview: missing column header, + thanks to Mario Rohkrämer +- Do not display "Your MySQL library..." if only the Z part of X.Y.Z version + is different +- bugs #1767759, 1216521 [data] Duplicate entry error Browse feature: this minor + feature removed due to its complexity +- bug #1774825 [operations] Rename database loses charset info +- bug #1791568 [core] Undefined cfg, thanks to Christian Schmidt +- bug #1782332 [structure] New table form does not overtake data +- bug #1793763 [requirements] minimum PHP should be 4.2.0 +- patch #1787915 Avoid CSS reloading on every click, thanks to Juergen Wind +- bug #1798627 [GUI] Wrong storage engine displayed + +2.11.0.0 (2007-08-21) ++ [import] support handling of DELIMITER to mimic mysql CLI, thanks to fb1 ++ improved PHP 6 compatibility +- bug #1674914 [structure] changing definition of a TIMESTAMP field +- bug #1615530 [upload] added more specific error message if field upload fails +- bug #1627210, #1083301, #1482401 [data] warning on duplicate indexes +- bug #1668724 JavaScript focus login Opera +- bug #1666657 [auth] Cookie password delete on timeout / inactivity +- bug #1648802 different mysql library and server version +- bug #1662976 [auth] Authentication fails when controluser/pass is set +- bug #1643758 [import] Error #1264 importing NULL values in MySQL 5.0 +- bug #1523747 [innodb] make warning about row count more visible +- bug #1676012 [auth] strip non-US-ASCII characters (RFC2616) +- bug #1679440 Added FAQ entry about header errors under IIS caused by + an end-of-line character +- [gui] avoid displaying a wide selector in server selection +- bug #1614004 [relation] foreign key spanning multiple columns are + incorrectly displayed +- bug #1681598 [interface] Edit next row +- bug #1688053 [export] Wrong export of binary character fields +- bug #1498281 [parser] Wrong primary key used for displaying results + with subquery +- bug #1699772 Visual space bug in table name (in browser) +- bug #1699532 Cause of data manipulation issues: implemented changes + as suggested by crisp_; still have to work on updating an ENUM value ++ [core] added PMA_fatalError() and made use of it +. [core] added PMA_isValid() and PMA_ifSetOr() for variable handling +. [i18n] use generic $strOptions +. [core] get rid of $propicon +. [core] globalized variables to be includable inside function in + libraries/select_lang.lib.php ++ [doc] changed all documentation in config.inc.php to phpDocumentor style ++ [data] support for CREATE VIEW from query results ++ [gui] dropped css/ folder and moved into root of PMA ++ [l10n] new: Sinhala, Macedonian ++ [export] YAML export (see yaml.org), thanks to Bryce Thornton ++ [upload] moved file upload functionality into own class ++ [upload] make use of $cfg['TempDir'] for file uploads ++ [server] improved display of binary logs ++ [data] better error handling in tbl_create.php ++ [routines] from Patch #1649881, thanks to Mike Beck ++ [querywindow] store sql history in session ++ [querywindow] sql history now without db too ++ [querywindow] tweaks in sql history view ++ [export] Native Excel (Spreadsheet_Excel_Writer) improvements, + thanks to Christian Schmidt ++ [doc] requirement of mcrypt on 64-bit, thanks to Isaac Bennetch ++ [lang] Danish update, thanks to Finn Sorensen ++ RFE #1435922 [gui] navigation frame shows listing of databases when none selected ++ [data] support BIT datatype (under mysqli), thanks to Christian Schmidt ++ [display] automatic confirmation for sort by key, thanks to Juergen Wind ++ [data] can now choose the number of insert rows ++ RFE #1704779 [gui] link documentation from login page ++ RFE #1513345 [setup] check control user connection during setup ++ [structure] TRIGGERS: display/edit/drop/SQL export ++ [browse] store browse state in session per query ++ [lang] Turkish update, thanks to Burak Yavuz ++ [lang] Galician update, thanks to Xosé Calvo ++ [lang] Brazilian-Portuguese update, thanks to Airon Luis Pereira ++ [gui] Insert/Edit: no longer display the Go button each 15 lines + but just at the end of a row ++ [gui] Query window: use verbose server name if any ++ [auth] patch #1712514 specify host for single signon, thanks to Thierry ++ [gui] Navigator for the db list in the navigation panel ++ [gui] Navigator for the table list in the content panel +- bug #1727138 HTML not encoded (more than 1000 characters) ++ [display] Support for MySQL 5.0.37 profiling ++ RFE #1743983 [gui] Replace $max_characters by a configurable param: + $cfg['MaxCharactersInDisplayedSQL'] +- bug #1746186 LeftLogoLink fails if set to some external site +. [transformations]: remove "auto-detect" MIME-type that was never implemented ++ [display] patch #1749705, Allow multibyte characters in number formatting, + thanks to garas +- bug #1747215 Export emits blanks at line ends +- bug #1751172 Do not export data when exporting a single VIEW ++ [lang] Swedish update, thanks to Björn T. Hallberg ++ [lang] Russian update, thanks to Victor Volkov and the php-myadmin.ru users ++ [privileges] Support password hashing on the Edit Privileges interface +- bug #1755339 Warn about rename dataase actually being copy/delete +- bug #1746921 Left frame shrinks on db change, thanks to Juergen Wind ++ [gui] Export: Select All/Unselect All over the choices, + thanks to Florian Schmitz ++ [lang] Japanese update, thanks to Ishigaki Kenichi +- bug #1759528 browse_foreigners fails due to newlines, + thanks to Hanno Boeck ++ [lang] Norwegian update, thanks to Sven-Erik Andersen ++ [lang] Italian update, thanks to Luca Rebellato ++ [lang] Spanish update, thanks to Daniel Hinostroza +. [export] Do not obey $cfg['MaxTableList'] on database export +- [doc] UploadDir and the Import tab, thanks to Juergen Wind +- bug #1766975 Parameters lost when editing stored routine +- [export] patch #1766633 Incorrect export with specified MySQL port, + thanks to Juergen Wind ++ [lang] Catalan update, thanks to Xavier Navarro +- bug #1751553 Drop-down instead of input when editing +- [data] foreign key browser: encoding mixups, thanks to Thijs Kinkhorst +- bug #1771721 Old SVN URLs + +2.10.3.0 (2007-07-20) +- bug #1734285 Copy database with VIEWs +- bug #1722502 DROP TABLE in export VIEW +- bug #1729027 Sorting results of VIEW browsing +- bug #1733012 Unwanted table alias in delete button +- bug #1736405 Pretty printer and HTML line breaks +- bug #1745257 Invalid DB name is still displayed +- bug #1730367 Calendar "Go" has no effect +- bug #1748633 Incorrect parameter validation for VIEWs ++ [lang] Russian revision, thanks to Victor Volkov and the users of + php-myadmin.ru +- Do not try to delete an internal relation if we just deleted an InnoDB one + +2.10.2.0 (2007-06-15) ++ [data] display all warnings, not only last one +- typo in fix for bug #1671813 +- bug #1714908 Inserted Row Count is wrong +- bug #1712570 Deleting last record freezes +- bug #1717339 Missing header when deleting a checked column, + thanks to Michael Keck +- bug #1717477 Warning on Query page when db is empty +- bug #1721002 db rename -> undefined cfgRelation, thanks to Jürgen Wind +- bug #1721571 CREATE database privilege not always detected, + thanks to Gordon McNaughton +- bug #1715709 export in SQL format always includes procedures and functions +- bug #1722502 DROP TABLE in export view structure +- bug #1718787 Multi-server setup breaks Designer +- bug #1724401 Column truncation in repair table output +- patch #1726500 Wrong position of , thanks to Jürgen Wind +- bug #1728590 Detected failing session_start fails, thanks to Jürgen Wind +- RFE #1714760 Obey ShowCreateDb on the Databases tab +- patch #1733762 Typo in message "INSERT DELAY", thanks to Victor Volkov +- patch #1730171 Dead message strLanguageFileNotFound, thanks to Victor Volkov +- patch #1731280 Avoid negative exponent in gmp_pow(), thanks to anosek + +2.10.1.0 (2007-04-23) +- bug #1541147 [js] '#' in database names not correctly handled by queywindow.js +- bug #1671403 [parser] using "client" as table name +- bug #1672379 [core] Call to undefined function PMA_removeCookie() +- bug [core] undefined variable in libraries/tbl_replace_fields.inc.php +- bug [gui] query window icon did not work, thanks to Jürgen Wind - windkiel +. [general] use PMA_getenv('PHP_SELF') +- bug #1676033 [core] pow(int,int) causes overflow +- bug #1680952 [core] undefined function PMA_getUvaCondition() +- bug #1596328 [export] drop support for POSTGRESQL compatibility mode +- bug #1609443 [privileges] Grant all priv. on wildcard name (fix message) +- bug #1567317 [sqp] Syntax highlighter: extra spaces +- bug #1239401 [sqp] table dot numeric field name +- bug #1672789 [sqp] Undefined offset: 4 in sqlparser.lib.php #1674 +- bug #1682044 [export] Export file even if file not selected +- bug #1664212 querywindow loses url encoded characters +- replaced ctype_digit() with is_numeric() ++ [config] clean cookies on phpMyAdmin upgrade +- bug #1674972 [export] no export with %afm% +- bug #1667887 HTML maxlength +- bug #1679055 #1050 - Table '