#2446 Login escape issues

2.10.0.2
fixed
5
2013-06-11
2007-05-31
No

I have hosting on a Cpanel based website that when I change my password to have anything with a '\' in it the login authentication fails. I dont have access to the phpMyAdmin source on that but I think that this bug, while minor, should be fixed as there may be other people that may find one like it.

Suggested fix: str_replace('\', '\\', $pmainput);

Discussion

  • Marc Delisle

    Marc Delisle - 2007-06-22

    Logged In: YES
    user_id=210714
    Originator: NO

    How do you authenticate? Is is done via CPanel or via phpMyAdmin?
    I can reproduce this problem when phpMyAdmin is configured with auth_type = 'http' which presents a browser HTTP authentication panel (but I don't have a CPanel environment).

     
  • Marc Delisle

    Marc Delisle - 2007-06-22
    • assigned_to: nobody --> lem9
     
  • Marc Delisle

    Marc Delisle - 2007-06-26
    • status: open --> pending
     
  • Dragon_Legion

    Dragon_Legion - 2007-07-05

    Logged In: YES
    user_id=1805160
    Originator: YES

    the authentication is done via Cpanel. I assume the password is set in a session or something similar but it might also be a Cpanel issue. My site admin posted this bug to them as well.

     
  • Dragon_Legion

    Dragon_Legion - 2007-07-05
    • status: pending --> open
     
  • Marc Delisle

    Marc Delisle - 2007-07-08

    Logged In: YES
    user_id=210714
    Originator: NO

    Let's see what CPanel has to say about this. I don't even know how they propagate the credentials to phpMyAdmin.

     
  • Marc Delisle

    Marc Delisle - 2007-07-08
    • status: open --> pending
     
  • SourceForge Robot

    • status: pending --> closed
     
  • SourceForge Robot

    Logged In: YES
    user_id=1312539
    Originator: NO

    This Tracker item was closed automatically by the system. It was
    previously set to a Pending status, and the original submitter
    did not respond within 14 days (the time period specified by
    the administrator of this Tracker).

     
  • Michal Čihař

    Michal Čihař - 2013-06-11
    • Status: closed --> fixed
     

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.





No, thanks