[php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string

From: Date: Tue, 05 Apr 2022 14:31:58 +0000
Subject: [php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240664@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8300
Comment Author: cmb69

Ugh, that's ugly (I don't think we should discuss details publicly, but we need to keep
these in mind).

Anyhow, I'm not sure what to do, though. If we would automatically escape (if that's even
possible in a portable way), that could easily break code which does the escaping manually. Adding
an INI setting is undesireable (same code, different behavior). For PDO_ODBC, we could add a
connection attribute, though. At the very least we should properly document the current behavior,
and maybe we should introduce an additional function for escaping.

> […]  perhaps it could warn/error out if user input is problematic.

So warn/error on unescaped ;? That might be the best immediate solution.


Thread (1 message)

  • cmb69
« previous php.bugs (#240664) next »