Bug #70042 [Ver->Nab]: FILTER_SANITIZE_STRING stripping out portion of string
| From: | cmb@php.net | Date: | Fri, 10 Jul 2015 15:36:14 +0000 |
| Subject: | Bug #70042 [Ver->Nab]: FILTER_SANITIZE_STRING stripping out portion of string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194314@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70042&edit=1
ID: 70042
Updated by: cmb@php.net
Reported by: tom dot noel at lgh-usa dot com
Summary: FILTER_SANITIZE_STRING stripping out portion of
string
-Status: Verified
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 5.6.11
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Actually, this is not a bug. FILTER_SANITIZE_STRING strips all
potential tags, and the input string contains the following tag:
<= '01') OR (expDateYear >
Previous Comments:
------------------------------------------------------------------------
[2015-07-10 15:01:30] cmb@php.net
Confirmed: <http://3v4l.org/KbRre>. Happens also on
Windows.
------------------------------------------------------------------------
[2015-07-10 14:17:05] tom dot noel at lgh-usa dot com
Description:
------------
When running a basic query through the filter_var function using FILTER_SANITIZE_STRING and
FILER_FLAG_NO_ENCODE_QUOTES a portion of my string is being stripped out that shouldn't be.
Test script:
---------------
$sql = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main
WHERE ((expDateYear = '2016' AND expDateMonth <= '01') OR (expDateYear >=
'2015' AND expDateMonth >= '07')) AND cardStatus = '1' AND
cardAuthorized = '1' ORDER BY kdaccount ASC LIMIT 0, 25";
$query = filter_var ($sql, FILTER_SANITIZE_STRING,
FILTER_FLAG_NO_ENCODE_QUOTES);die;
Expected result:
----------------
Should be identical to original string:
$query = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main
WHERE ((expDateYear = '2016' AND expDateMonth <= '01') OR (expDateYear >=
'2015' AND expDateMonth >= '07')) AND cardStatus = '1' AND
cardAuthorized = '1' ORDER BY kdaccount ASC LIMIT 0, 25"
Actual result:
--------------
$query = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main
WHERE ((expDateYear = '2016' AND expDateMonth = '2015' AND expDateMonth >=
'07')) AND cardStatus = '1' AND cardAuthorized = '1' ORDER BY
kdaccount ASC LIMIT 0, 25"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70042&edit=1