Req #47607 [Asn->Csd]: Add LDAP escaping

From: Date: Wed, 23 Oct 2013 08:47:45 +0000
Subject: Req #47607 [Asn->Csd]: Add LDAP escaping
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182404@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=47607&edit=1 ID: 47607 Updated by: daverandom@php.net Reported by: gdr at go2 dot pl Summary: Add LDAP escaping -Status: Assigned +Status: Closed Type: Feature/Change Request Package: LDAP related Operating System: * PHP Version: * Assigned To: daverandom Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2009-03-09 21:41:55] gdr at go2 dot pl One implementation of this function in PHP, found here: http://lists.evolvis.org/pipermail/evolvis-commits/2008-November/000054.html is: + function ldap_escape_string($string) //public + { + $string = str_replace(",", '\\,', $string); + $string = str_replace('"', '\\"', $string); + $string = str_replace("'", '\\\'', $string); + $string = str_replace("<", '\\<', $string); + $string = str_replace(">", '\\>', $string); + $string = str_replace(";", '\\;', $string); + $string = str_replace('\\', '\\\\', $string); + $string = str_replace("+", '\\+,', $string); + $string = str_replace("=", '\\=,', $string); + $string = str_replace("#", '\\#', $string); + return $string; + } I haven't, however, read RFC for this and therefore I don't know if it's 100% correct. ------------------------------------------------------------------------ [2009-03-09 17:36:36] gdr at go2 dot pl Description: ------------ The LDAP module needs a function to escape strings to prevent LDAP injections, like MySQL module has mysql_escape_string() Reproduce code: --------------- $sr=ldap_search($ds, "", "(sn=$_GET[lastname])"); Expected result: ---------------- $sr=ldap_search($ds, "", "(sn=".ldap_escape_string($_GET[lastname]).")"); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=47607&edit=1

« previous php.bugs (#182404) next »