Bug #75978 [Fbk->Csd]: Improper parsing

From: Date: Tue, 20 Feb 2018 02:39:53 +0000
Subject: Bug #75978 [Fbk->Csd]: Improper parsing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214041@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75978&edit=1

 ID:                 75978
 Updated by:         peehaa@php.net
 Reported by:        fwilliams22 at gmail dot com
 Summary:            Improper parsing
-Status:             Feedback
+Status:             Closed
 Type:               Bug
 Package:            Strings related
 Operating System:   Windows/Linux
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        peehaa
 Block user comment: N
 Private report:     N

 New Comment:

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php


Previous Comments:
------------------------------------------------------------------------
[2018-02-18 20:24:59] spam2 at rhsoft dot net

hell, learn about value escaping which are basics when you deal with databases

every non hardcoded input is untrusted and bad until the opposite is prove3

------------------------------------------------------------------------
[2018-02-18 20:01:48] peehaa@php.net

> "CVS" string processing fails to properly parse " (quote) delimited fields.

Works fine: https://3v4l.org/uEUO0

------------------------------------------------------------------------
[2018-02-18 20:00:32] peehaa@php.net

It's a bit hard to understand what the problem is reporting, but by the looks of it it's
just an SQL injection by yourself?

Use prepared statements so you don't have these problems.

------------------------------------------------------------------------
[2018-02-18 19:49:26] fwilliams22 at gmail dot com

Description:
------------
"CVS" string processing fails to properly parse " (quote) delimited fields.
delimited fields containing an ' (apostrophe) fail to parse correctly.  Appears that parser
recognizes an embedded apostrophe as a field delimiter.

My workaround is:

while (($data = fgets($handle, 500))) {
	$data = str_replace("'","\\'",$data);				
        $data = str_getcsv($data, ",",'"');
	$query = "INSERT INTO address 
          
(fname,lname,address,city,state,"
.
	   "postcode,aux)".
           " VALUES
'$data[0]','$data[1]','$data[2]','$data[3]'," .
           "'$data[4]','$data[5]','$data[6]');";
	$result = $db->exec($query);

Not all test cases seem to fail.  I have had to use the above workaround to update a MySQL table. 
The below example test script seems to have worked leaving "\\'" in the test field?

Anyhow that's my story and I'm sticking to it.

Could be the issue is in the PDO MySQL driver?

One of 'em needs more testing.



Test script:
---------------
$data = "\"Got'ta apostrophe you can spare?\"";
$data = str_replace("'","\\'",$data);				
$data = str_getcsv($data, ",",'"');




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75978&edit=1


Thread (5 messages)

« previous php.bugs (#214041) next »