Bug #77729 [NEW]: SECURITY BUG: SQL Injection with PDO::quote()

From: Date: Tue, 12 Mar 2019 19:38:53 +0000
Subject: Bug #77729 [NEW]: SECURITY BUG: SQL Injection with PDO::quote()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219933@lists.php.net to get a copy of this message
From: bogdanteleru at yahoo dot com Operating system: MacOS Mojave v10.14.3 PHP version: 7.2.16 Package: PDO MySQL Bug Type: Bug Bug description:SECURITY BUG: SQL Injection with PDO::quote() Description: ------------ --- From manual page: https://php.net/pdo.quote --- Running PDO::quote() on a string which ends in a quote (e.g. Naughty ' string') will result in a string which ends in an escaped quote (e.g. 'Naughty \' string\'). This opens a door to SQL injection; see the vulnerability example in the 'Test script' box, below. Test script: --------------- $name = '; DROP TABLE test_table; --\''; // Sample PDO connection; can be whatever $conn = new PDO('sqlite:/home/lynn/music.sql3'); $query = "SELECT * FROM students WHERE first_name = '%s' OR last_name = '%s'"; $query = sprintf($query, $conn->quote($name), $conn->quote($name)); echo $query; Expected result: ---------------- I'm expecting the PHP script to echo the following string: SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\'' OR last_name = '; DROP TABLE test_table; --\'' However, as seen in the 'Actual result' box, it's missing the end quote each time $name was inserted into the query string. This happens because PDO::quote() doesn't add the end quote if the original string already ends in a quote, as explained in the 'Description' box. Actual result: -------------- The script will echo: SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\' OR last_name = '; DROP TABLE test_table; --\' The above is basically two MySQL queries: 1. SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\' OR last_name = '; 2. DROP TABLE test_table; // dangerous -- Edit bug report at https://bugs.php.net/bug.php?id=77729&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77729&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77729&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77729&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77729&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77729&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77729&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77729&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77729&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77729&r=support Expected behavior: https://bugs.php.net/fix.php?id=77729&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77729&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77729&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77729&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77729&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77729&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77729&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77729&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77729&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77729&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77729&r=mysqlcfg

« previous php.bugs (#219933) next »