Bug #70042 [Ver->Nab]: FILTER_SANITIZE_STRING stripping out portion of string

From: Date: Fri, 10 Jul 2015 15:36:14 +0000
Subject: Bug #70042 [Ver->Nab]: FILTER_SANITIZE_STRING stripping out portion of string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194314@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70042&edit=1 ID: 70042 Updated by: cmb@php.net Reported by: tom dot noel at lgh-usa dot com Summary: FILTER_SANITIZE_STRING stripping out portion of string -Status: Verified +Status: Not a bug Type: Bug Package: *General Issues Operating System: * PHP Version: 5.6.11 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Actually, this is not a bug. FILTER_SANITIZE_STRING strips all potential tags, and the input string contains the following tag: <= '01') OR (expDateYear > Previous Comments: ------------------------------------------------------------------------ [2015-07-10 15:01:30] cmb@php.net Confirmed: <http://3v4l.org/KbRre>. Happens also on Windows. ------------------------------------------------------------------------ [2015-07-10 14:17:05] tom dot noel at lgh-usa dot com Description: ------------ When running a basic query through the filter_var function using FILTER_SANITIZE_STRING and FILER_FLAG_NO_ENCODE_QUOTES a portion of my string is being stripped out that shouldn't be. Test script: --------------- $sql = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main WHERE ((expDateYear = '2016' AND expDateMonth <= '01') OR (expDateYear >= '2015' AND expDateMonth >= '07')) AND cardStatus = '1' AND cardAuthorized = '1' ORDER BY kdaccount ASC LIMIT 0, 25"; $query = filter_var ($sql, FILTER_SANITIZE_STRING, FILTER_FLAG_NO_ENCODE_QUOTES);die; Expected result: ---------------- Should be identical to original string: $query = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main WHERE ((expDateYear = '2016' AND expDateMonth <= '01') OR (expDateYear >= '2015' AND expDateMonth >= '07')) AND cardStatus = '1' AND cardAuthorized = '1' ORDER BY kdaccount ASC LIMIT 0, 25" Actual result: -------------- $query = "SELECT customer, kdaccount, expDateMonth, expDateYear, nameid FROM creditcard_main WHERE ((expDateYear = '2016' AND expDateMonth = '2015' AND expDateMonth >= '07')) AND cardStatus = '1' AND cardAuthorized = '1' ORDER BY kdaccount ASC LIMIT 0, 25" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70042&edit=1

« previous php.bugs (#194314) next »