Bug #74220 [Com]: Special crafted SQL statement trips PDO

From: Date: Wed, 08 Mar 2017 12:14:11 +0000
Subject: Bug #74220 [Com]: Special crafted SQL statement trips PDO
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207745@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74220&edit=1 ID: 74220 Comment by: mfischer@php.net Reported by: mfischer@php.net Summary: Special crafted SQL statement trips PDO Status: Open Type: Bug Package: PDO PgSQL Operating System: Ubuntu 14.04 PHP Version: 7.1.2 Block user comment: N Private report: N New Comment: Not sure if I missed something obvious. For now I found multiple ways to make it work: 1. use prepared statements (i.e. use :name or ? placeholder, etc.) 2. set the PDO flag PDO::ATTR_EMULATE_PREPARES to true 3. apply pgsql C-Style escape syntax [1], i.e. VALUES(E'\\'':1) About 2): this worked for simple cases but failed in a large application, didn't yet investigate why About 3): haven't dug deeper whether this can cause more troubles or not [1] https://www.postgresql.org/docs/9.6/static/sql-syntax-lexical.html#SQL-SYNTAX-STRINGS-ESCAPE Previous Comments: ------------------------------------------------------------------------ [2017-03-07 22:34:16] mfischer@php.net Description: ------------ I initially reported this at https://github.com/cakephp/cakephp/issues/10373 but was told "If you can reproduce this issue with raw PDO, then its not a CakePHP issue." The provided SQL statement, as executed with PDO, does not insert the provided data correctly. Prerequisites: create a db role / database table: postgres=# create role username login password 'password'; CREATE ROLE postgres=# create database db owner username; CREATE DATABASE postgres=# \c db You are now connected to database "db" as user "postgres". db=# set role username; SET db=> create table models(field varchar(12)); CREATE TABLE The provided SQL statement (see test script) is valid Postgres syntax. Test script: --------------- <?php $pdo = new PDO('pgsql:host=localhost;dbname=db', 'username', 'password'); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $sql = <<<SQL INSERT INTO models (field) values('\'':1'); SQL; $pdo->query($sql); $result = $pdo->query('SELECT * FROM models'); var_dump($result->fetchAll()); Expected result: ---------------- array(1) { [0]=> array(2) { ["field"]=> string(4) "\':1" [0]=> string(4) "\':1" } } Actual result: -------------- array(1) { [0]=> array(2) { ["field"]=> string(4) "\'$1" [0]=> string(4) "\'$1" } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74220&edit=1

« previous php.bugs (#207745) next »