Bug #72225 [Com]: NULL is not correct escaped by mysqli.real-escape-string
| From: | dc at ftb-esv dot de | Date: | Wed, 18 May 2016 07:59:16 +0000 |
| Subject: | Bug #72225 [Com]: NULL is not correct escaped by mysqli.real-escape-string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201171@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72225&edit=1
ID: 72225
Comment by: dc at ftb-esv dot de
Reported by: dc at ftb-esv dot de
Summary: NULL is not correct escaped by
mysqli.real-escape-string
Status: Not a bug
Type: Bug
Package: MySQLi related
Operating System: Linux
PHP Version: 5.5.35
Block user comment: N
Private report: N
New Comment:
With this new knowledge (mysql don't support octal escapes) I found the bug in a class of my
company.
Thanks for response.
Previous Comments:
------------------------------------------------------------------------
[2016-05-16 17:55:28] requinix@php.net
MySQL does not have octal escape sequences.
mysql> SELECT "a\01b";
+------+
| a |
+------+
| a 1b |
+------+
1 row in set (0.00 sec)
mysql> SELECT HEX("a\01b");
+--------------+
| HEX("a\01b") |
+--------------+
| 61003162 |
+--------------+
1 row in set (0.07 sec)
------------------------------------------------------------------------
[2016-05-16 17:27:45] dc at ftb-esv dot de
Description:
------------
---
From manual page: http://www.php.net/mysqli.real-escape-string
---
real_escape_string escapes a NULL to "\0", but this is wrong!
It must be escaped to "\000" or conversions are wrong, if a digit follows.
Test script:
---------------
$a = "a\000" . "1b";
echo mysqli->real_escape_string($a);
RESULT:
a\01b => 'a' . '\01' . 'b'
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72225&edit=1