Bug #72225 [Com]: NULL is not correct escaped by mysqli.real-escape-string

From: Date: Wed, 18 May 2016 07:59:16 +0000
Subject: Bug #72225 [Com]: NULL is not correct escaped by mysqli.real-escape-string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201171@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72225&edit=1 ID: 72225 Comment by: dc at ftb-esv dot de Reported by: dc at ftb-esv dot de Summary: NULL is not correct escaped by mysqli.real-escape-string Status: Not a bug Type: Bug Package: MySQLi related Operating System: Linux PHP Version: 5.5.35 Block user comment: N Private report: N New Comment: With this new knowledge (mysql don't support octal escapes) I found the bug in a class of my company. Thanks for response. Previous Comments: ------------------------------------------------------------------------ [2016-05-16 17:55:28] requinix@php.net MySQL does not have octal escape sequences. mysql> SELECT "a\01b"; +------+ | a | +------+ | a 1b | +------+ 1 row in set (0.00 sec) mysql> SELECT HEX("a\01b"); +--------------+ | HEX("a\01b") | +--------------+ | 61003162 | +--------------+ 1 row in set (0.07 sec) ------------------------------------------------------------------------ [2016-05-16 17:27:45] dc at ftb-esv dot de Description: ------------ --- From manual page: http://www.php.net/mysqli.real-escape-string --- real_escape_string escapes a NULL to "\0", but this is wrong! It must be escaped to "\000" or conversions are wrong, if a digit follows. Test script: --------------- $a = "a\000" . "1b"; echo mysqli->real_escape_string($a); RESULT: a\01b => 'a' . '\01' . 'b' ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72225&edit=1

« previous php.bugs (#201171) next »