Bug #36870 [Com]: odbc_execute can't insert a string that starts and ends with a single quote
| From: | lehmann at cnm dot de | Date: | Tue, 26 Jan 2016 14:42:06 +0000 |
| Subject: | Bug #36870 [Com]: odbc_execute can't insert a string that starts and ends with a single quote | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198904@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=36870&edit=1
ID: 36870
Comment by: lehmann at cnm dot de
Reported by: mjs at beebo dot org
Summary: odbc_execute can't insert a string that starts and
ends with a single quote
Status: Not a bug
Type: Bug
Package: ODBC related
Operating System: Windows
PHP Version: 5.1.2
Block user comment: N
Private report: N
New Comment:
Just because something is documented, it is not a desirable feature. I'm pretty sure that most
of the database developers - although the documentation formally exists - are not aware of this
unexpected weirdness.
If it was a feature, you could explicitly decide to use it. In this case however, you cannot even
opt-out or disable it. You are forced to use the less secure odbc_exec() instead, which doesn't
allow prepared statements. Or you are forced to code workarounds like adding a blank to the string
on PHP side and use RTRIM(?) on database side to remove it.
So while 0,01% of the developers may find this feature useful, 99,99% won't even be aware of it
and introduce a security hole into their applications unwillingly. I think it's time to clean
up and make those rare users make us of file_get_contents() instead.
Previous Comments:
------------------------------------------------------------------------
[2006-04-10 00:40:40] edink@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
This is documented limitation. See http://www.php.net/manual/en/function.odbc-execute.php
------------------------------------------------------------------------
[2006-03-27 12:08:11] mjs at beebo dot org
Description:
------------
odbc_execute has a feature whereby if the string to be inserted starts and ends with a single quote,
the string is interpreted as a filename whose contents are interpreted as the value of the
placeholder.
There does not appear to be a way to insert a string that begins and ends with a single
quote--neither backslashing nor double-quoting works, and it appears from reading the source
(php_odbc.c:1014) that nothing else will either.
Reproduce code:
---------------
$sth = odbc_prepare($dbh, "INSERT INTO people(name) VALUES(?)");
$res = odbc_execute($sth, array('\'The Count\''));
Expected result:
----------------
The string \'The Count\' inserted into the database.
Actual result:
--------------
The string is interpreded as a filename, resulting in the erro "Can't open file XXX"
in the error log.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=36870&edit=1