[php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string

From: Date: Tue, 05 Apr 2022 15:15:33 +0000
Subject: [php-src] Issue #8300: Procedural and PDO ODBC don't escape user input when building connection string
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240666@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8300
Comment Author: NattyNarwhal

So the documentation for
[SQLBrowseConnect](https://docs.microsoft.com/en-us/sql/odbc/reference/syntax/sqlbrowseconnect-function?view=sql-server-ver15#outconnectionstring-argument)
and
[SQLDriverConnect](https://docs.microsoft.com/en-us/sql/odbc/reference/syntax/sqldriverconnect-function?view=sql-server-ver15#comments)
seem to imply that braces are strongly recommended to be handled by drivers? If that's the
case, I wonder if always wrapping in curly braces is OK. If so, PHP can do that, and if the user is
already wrapping the value (just check first and last char if they're braces), don't touch
it.

Do agree checking for ; is OK for an interim solution, but do we need to check for
others?


Thread (1 message)

  • NattyNarwhal
« previous php.bugs (#240666) next »