Req #68856 [Opn->Ver]: add arg to odbc_execute() so values not treated as filenames

From: Date: Mon, 05 Oct 2020 13:02:54 +0000
Subject: Req #68856 [Opn->Ver]: add arg to odbc_execute() so values not treated as filenames
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229400@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68856&edit=1 ID: 68856 Updated by: cmb@php.net Reported by: j dot faithw at yahoo dot com Summary: add arg to odbc_execute() so values not treated as filenames -Status: Open +Status: Verified Type: Feature/Change Request Package: ODBC related PHP Version: 5.6.4 Block user comment: N Private report: N New Comment: I agree that this "feature" raises potential security concerns. The suggested solution to add an optional $filenames parameter might be a viable workaround for now, but in the long run parameters enclosed in single-quotes should not be treated as filenames at all, but rather that should be catered to by special objects, similar to what has been done for CURLOPT_POSTFIELDS by introducing the CURLFile class. Previous Comments: ------------------------------------------------------------------------ [2015-01-19 13:04:55] j dot faithw at yahoo dot com Description: ------------ currently odbc_execute is declared as:- bool odbc_execute ( resource $result_id [, array $parameters_array ] ) But parameters_array has a quirk i.e:- Any parameters in parameter_array which start and end with single quotes will be taken as the name of a file to read and send to the database server as the data for the appropriate placeholder. I suggest that an additional argument be added i.e. bool odbc_execute ( resource $result_id [, array $parameters_array [, mixed $filenames = true ]] ) By default $filenames would be true and the existing functionality will be unchanged. But if false the values in $parameters_array will never be interpreted as filenames. Also $filenames could be an array of true/false values specifying for each element of $parameters_array if the value should be interpreted as a filename. This change would allow odbc_prepare and odbc_execute to be used more often, in particular to help protect against SQL injection attacks which odbc_exec is prone to. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68856&edit=1

« previous php.bugs (#229400) next »