Merged in victorsl/processmaker/HOR-1957-31 (pull request #4966)
HOR-1957
This commit is contained in:
@@ -405,7 +405,7 @@ class DataBaseMaintenance
|
|||||||
$dbPort = $aHost[1];
|
$dbPort = $aHost[1];
|
||||||
$command = 'mysqldump'
|
$command = 'mysqldump'
|
||||||
. ' --user=' . $this->user
|
. ' --user=' . $this->user
|
||||||
. ' --password=' . str_replace('"', '\"', str_replace("'", "\'", quotemeta($this->passwd)))
|
. ' --password=' . escapeshellarg($this->passwd)
|
||||||
. ' --host=' . $dbHost
|
. ' --host=' . $dbHost
|
||||||
. ' --port=' . $dbPort
|
. ' --port=' . $dbPort
|
||||||
. ' --opt'
|
. ' --opt'
|
||||||
@@ -418,7 +418,7 @@ class DataBaseMaintenance
|
|||||||
. ' --user=' . $this->user
|
. ' --user=' . $this->user
|
||||||
. ' --opt'
|
. ' --opt'
|
||||||
. ' --skip-comments'
|
. ' --skip-comments'
|
||||||
. ' --password=' . str_replace('"', '\"', str_replace("'", "\'", quotemeta($this->passwd)))
|
. ' --password=' . escapeshellarg($this->passwd)
|
||||||
. ' ' . $this->dbName
|
. ' ' . $this->dbName
|
||||||
. ' > ' . $outfile;
|
. ' > ' . $outfile;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1402,7 +1402,7 @@ class workspaceTools
|
|||||||
. ' --host=' . $dbHost
|
. ' --host=' . $dbHost
|
||||||
. ' --port=' . $dbPort
|
. ' --port=' . $dbPort
|
||||||
. ' --user=' . $parameters['dbUser']
|
. ' --user=' . $parameters['dbUser']
|
||||||
. ' --password=' . str_replace('"', '\"', str_replace("'", "\'", quotemeta($parameters['dbPass'])))//no change! supports the type passwords: .\+*?[^]($)'"\"'
|
. ' --password=' . escapeshellarg($parameters['dbPass'])
|
||||||
. ' --database=' . mysql_real_escape_string($database)
|
. ' --database=' . mysql_real_escape_string($database)
|
||||||
. ' --default_character_set utf8'
|
. ' --default_character_set utf8'
|
||||||
. ' --execute="SOURCE ' . $filename . '"';
|
. ' --execute="SOURCE ' . $filename . '"';
|
||||||
@@ -1410,7 +1410,7 @@ class workspaceTools
|
|||||||
$command = 'mysql'
|
$command = 'mysql'
|
||||||
. ' --host=' . $dbHost
|
. ' --host=' . $dbHost
|
||||||
. ' --user=' . $parameters['dbUser']
|
. ' --user=' . $parameters['dbUser']
|
||||||
. ' --password=' . str_replace('"', '\"', str_replace("'", "\'", quotemeta($parameters['dbPass'])))//no change! supports the type passwords: .\+*?[^]($)'"\"'
|
. ' --password=' . escapeshellarg($parameters['dbPass'])
|
||||||
. ' --database=' . mysql_real_escape_string($database)
|
. ' --database=' . mysql_real_escape_string($database)
|
||||||
. ' --default_character_set utf8'
|
. ' --default_character_set utf8'
|
||||||
. ' --execute="SOURCE ' . $filename . '"';
|
. ' --execute="SOURCE ' . $filename . '"';
|
||||||
|
|||||||
Reference in New Issue
Block a user