Don't allow path in HTTP servers

This commit is contained in:
Jakub Vrana
2025-02-18 07:58:27 +01:00
parent d9289355d7
commit 578c9fca92
4 changed files with 22 additions and 17 deletions

View File

@@ -248,7 +248,10 @@ if (isset($_GET["simpledb"])) {
function connect() {
global $adminer;
list(, , $password) = $adminer->credentials();
list($host, , $password) = $adminer->credentials();
if (!preg_match('~^(https?://)?[-a-z\d.]+(:\d+)?$~', $host)) {
return lang('Invalid server.');
}
if ($password != "") {
return lang('Database does not support password.');
}