Req #47607 [Asn->Csd]: Add LDAP escaping
| From: | daverandom@php.net | Date: | Wed, 23 Oct 2013 08:47:45 +0000 |
| Subject: | Req #47607 [Asn->Csd]: Add LDAP escaping | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182404@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=47607&edit=1
ID: 47607
Updated by: daverandom@php.net
Reported by: gdr at go2 dot pl
Summary: Add LDAP escaping
-Status: Assigned
+Status: Closed
Type: Feature/Change Request
Package: LDAP related
Operating System: *
PHP Version: *
Assigned To: daverandom
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2009-03-09 21:41:55] gdr at go2 dot pl
One implementation of this function in PHP, found here:
http://lists.evolvis.org/pipermail/evolvis-commits/2008-November/000054.html
is:
+ function ldap_escape_string($string) //public
+ {
+ $string = str_replace(",", '\\,', $string);
+ $string = str_replace('"', '\\"', $string);
+ $string = str_replace("'", '\\\'', $string);
+ $string = str_replace("<", '\\<', $string);
+ $string = str_replace(">", '\\>', $string);
+ $string = str_replace(";", '\\;', $string);
+ $string = str_replace('\\', '\\\\', $string);
+ $string = str_replace("+", '\\+,', $string);
+ $string = str_replace("=", '\\=,', $string);
+ $string = str_replace("#", '\\#', $string);
+ return $string;
+ }
I haven't, however, read RFC for this and therefore I don't know if it's 100%
correct.
------------------------------------------------------------------------
[2009-03-09 17:36:36] gdr at go2 dot pl
Description:
------------
The LDAP module needs a function to escape strings to prevent LDAP injections, like MySQL module has
mysql_escape_string()
Reproduce code:
---------------
$sr=ldap_search($ds, "", "(sn=$_GET[lastname])");
Expected result:
----------------
$sr=ldap_search($ds, "",
"(sn=".ldap_escape_string($_GET[lastname]).")");
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=47607&edit=1