Bug #36870 [Com]: odbc_execute can't insert a string that starts and ends with a single quote

From: Date: Tue, 26 Jan 2016 14:42:06 +0000
Subject: Bug #36870 [Com]: odbc_execute can't insert a string that starts and ends with a single quote
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198904@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=36870&edit=1 ID: 36870 Comment by: lehmann at cnm dot de Reported by: mjs at beebo dot org Summary: odbc_execute can't insert a string that starts and ends with a single quote Status: Not a bug Type: Bug Package: ODBC related Operating System: Windows PHP Version: 5.1.2 Block user comment: N Private report: N New Comment: Just because something is documented, it is not a desirable feature. I'm pretty sure that most of the database developers - although the documentation formally exists - are not aware of this unexpected weirdness. If it was a feature, you could explicitly decide to use it. In this case however, you cannot even opt-out or disable it. You are forced to use the less secure odbc_exec() instead, which doesn't allow prepared statements. Or you are forced to code workarounds like adding a blank to the string on PHP side and use RTRIM(?) on database side to remove it. So while 0,01% of the developers may find this feature useful, 99,99% won't even be aware of it and introduce a security hole into their applications unwillingly. I think it's time to clean up and make those rare users make us of file_get_contents() instead. Previous Comments: ------------------------------------------------------------------------ [2006-04-10 00:40:40] edink@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php This is documented limitation. See http://www.php.net/manual/en/function.odbc-execute.php ------------------------------------------------------------------------ [2006-03-27 12:08:11] mjs at beebo dot org Description: ------------ odbc_execute has a feature whereby if the string to be inserted starts and ends with a single quote, the string is interpreted as a filename whose contents are interpreted as the value of the placeholder. There does not appear to be a way to insert a string that begins and ends with a single quote--neither backslashing nor double-quoting works, and it appears from reading the source (php_odbc.c:1014) that nothing else will either. Reproduce code: --------------- $sth = odbc_prepare($dbh, "INSERT INTO people(name) VALUES(?)"); $res = odbc_execute($sth, array('\'The Count\'')); Expected result: ---------------- The string \'The Count\' inserted into the database. Actual result: -------------- The string is interpreded as a filename, resulting in the erro "Can't open file XXX" in the error log. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=36870&edit=1

« previous php.bugs (#198904) next »