Req #68856 [Opn->Ver]: add arg to odbc_execute() so values not treated as filenames
| From: | cmb@php.net | Date: | Mon, 05 Oct 2020 13:02:54 +0000 |
| Subject: | Req #68856 [Opn->Ver]: add arg to odbc_execute() so values not treated as filenames | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229400@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68856&edit=1
ID: 68856
Updated by: cmb@php.net
Reported by: j dot faithw at yahoo dot com
Summary: add arg to odbc_execute() so values not treated as
filenames
-Status: Open
+Status: Verified
Type: Feature/Change Request
Package: ODBC related
PHP Version: 5.6.4
Block user comment: N
Private report: N
New Comment:
I agree that this "feature" raises potential security concerns.
The suggested solution to add an optional $filenames parameter
might be a viable workaround for now, but in the long run
parameters enclosed in single-quotes should not be treated as
filenames at all, but rather that should be catered to by special
objects, similar to what has been done for CURLOPT_POSTFIELDS by
introducing the CURLFile class.
Previous Comments:
------------------------------------------------------------------------
[2015-01-19 13:04:55] j dot faithw at yahoo dot com
Description:
------------
currently odbc_execute is declared as:-
bool odbc_execute ( resource $result_id [, array $parameters_array ] )
But parameters_array has a quirk i.e:-
Any parameters in parameter_array which start and end with single quotes will be taken as the
name of a file to read and send to the database server as the data for the appropriate placeholder.
I suggest that an additional argument be added i.e.
bool odbc_execute ( resource $result_id [, array $parameters_array [, mixed $filenames = true ]] )
By default $filenames would be true and the existing functionality will be unchanged. But if false
the values in $parameters_array will never be interpreted as filenames. Also $filenames could be an
array of true/false values specifying for each element of $parameters_array if the value should be
interpreted as a filename.
This change would allow odbc_prepare and odbc_execute to be used more often, in particular to help
protect against SQL injection attacks which odbc_exec is prone to.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68856&edit=1