Bug #75978 [Opn->Fbk]: Improper parsing
| From: | peehaa@php.net | Date: | Sun, 18 Feb 2018 20:00:33 +0000 |
| Subject: | Bug #75978 [Opn->Fbk]: Improper parsing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214010@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75978&edit=1
ID: 75978
Updated by: peehaa@php.net
Reported by: fwilliams22 at gmail dot com
Summary: Improper parsing
-Status: Open
+Status: Feedback
Type: Bug
Package: Strings related
Operating System: Windows/Linux
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
It's a bit hard to understand what the problem is reporting, but by the looks of it it's
just an SQL injection by yourself?
Use prepared statements so you don't have these problems.
Previous Comments:
------------------------------------------------------------------------
[2018-02-18 19:49:26] fwilliams22 at gmail dot com
Description:
------------
"CVS" string processing fails to properly parse " (quote) delimited fields.
delimited fields containing an ' (apostrophe) fail to parse correctly. Appears that parser
recognizes an embedded apostrophe as a field delimiter.
My workaround is:
while (($data = fgets($handle, 500))) {
$data = str_replace("'","\\'",$data);
$data = str_getcsv($data, ",",'"');
$query = "INSERT INTO
address
(fname,lname,address,city,state,"
.
"postcode,aux)".
" VALUES
'$data[0]','$data[1]','$data[2]','$data[3]'," .
"'$data[4]','$data[5]','$data[6]');";
$result = $db->exec($query);
Not all test cases seem to fail. I have had to use the above workaround to update a MySQL table.
The below example test script seems to have worked leaving "\\'" in the test field?
Anyhow that's my story and I'm sticking to it.
Could be the issue is in the PDO MySQL driver?
One of 'em needs more testing.
Test script:
---------------
$data = "\"Got'ta apostrophe you can spare?\"";
$data = str_replace("'","\\'",$data);
$data = str_getcsv($data, ",",'"');
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75978&edit=1