[php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building
| From: | NattyNarwhal | Date: | Mon, 04 Apr 2022 21:14:12 +0000 |
| Subject: | [php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-240659@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8300
Comment Author: NattyNarwhal
You can also use curly braces or single quotes wrapping the password in the third arg as a weak
attempt to mitigate. It also gives you other fun opportunities for injection, like:
```
$connection = odbc_pconnect('Driver=MariaDB;Database=lobsters_dev', 'foobar',
"{pass;word};Port=1337");
````