Bug #77729 [Csd->Nab]: SECURITY BUG: SQL Injection with PDO::quote()

From: Date: Tue, 12 Mar 2019 21:37:33 +0000
Subject: Bug #77729 [Csd->Nab]: SECURITY BUG: SQL Injection with PDO::quote()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219937@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77729&edit=1 ID: 77729 Updated by: requinix@php.net Reported by: bogdanteleru at yahoo dot com Summary: SECURITY BUG: SQL Injection with PDO::quote() -Status: Closed +Status: Not a bug Type: Bug Package: PDO MySQL Operating System: MacOS Mojave v10.14.3 PHP Version: 7.2.16 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2019-03-12 19:46:01] bogdanteleru at yahoo dot com Closed ------------------------------------------------------------------------ [2019-03-12 19:45:47] bogdanteleru at yahoo dot com Nevermind, there's no actual bug. ------------------------------------------------------------------------ [2019-03-12 19:38:53] bogdanteleru at yahoo dot com Description: ------------ --- From manual page: https://php.net/pdo.quote --- Running PDO::quote() on a string which ends in a quote (e.g. Naughty ' string') will result in a string which ends in an escaped quote (e.g. 'Naughty \' string\'). This opens a door to SQL injection; see the vulnerability example in the 'Test script' box, below. Test script: --------------- $name = '; DROP TABLE test_table; --\''; // Sample PDO connection; can be whatever $conn = new PDO('sqlite:/home/lynn/music.sql3'); $query = "SELECT * FROM students WHERE first_name = '%s' OR last_name = '%s'"; $query = sprintf($query, $conn->quote($name), $conn->quote($name)); echo $query; Expected result: ---------------- I'm expecting the PHP script to echo the following string: SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\'' OR last_name = '; DROP TABLE test_table; --\'' However, as seen in the 'Actual result' box, it's missing the end quote each time $name was inserted into the query string. This happens because PDO::quote() doesn't add the end quote if the original string already ends in a quote, as explained in the 'Description' box. Actual result: -------------- The script will echo: SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\' OR last_name = '; DROP TABLE test_table; --\' The above is basically two MySQL queries: 1. SELECT * FROM students WHERE first_name = '; DROP TABLE test_table; --\' OR last_name = '; 2. DROP TABLE test_table; // dangerous ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77729&edit=1

« previous php.bugs (#219937) next »