#46011 [Opn]: mysql_real_escape_string is no protection for numeric fields

From: Date: Tue, 30 Sep 2008 10:26:10 +0000
Subject: #46011 [Opn]: mysql_real_escape_string is no protection for numeric fields
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-1179@lists.php.net to get a copy of this message
ID: 46011 User updated by: pablo dot angulo at uam dot es Reported By: pablo dot angulo at uam dot es Status: Open Bug Type: Documentation problem Operating System: Irrelevant PHP Version: Irrelevant New Comment: "http://php.net/manual/en/function.mysql-query.php should really contain a warning about SQL injection." absolutely agree "Even better, mysql_query should be deprecated and replaced by a safe(r) variant." That may be too radical, as there are CMS that rely on this function and provide (I hope) safety wrappers around mysql calls. Also, many times there is no user input in a mysql call. Previous Comments: ------------------------------------------------------------------------ [2008-09-30 09:20:46] olafvdspek at gmail dot com http://php.net/manual/en/function.mysql-query.php should really contain a warning about SQL injection. Even better, mysql_query should be deprecated and replaced by a safe(r) variant. ------------------------------------------------------------------------ [2008-09-06 17:34:26] pablo dot angulo at uam dot es Description: ------------ mysql_real_escape_string documentation gives the false impression that its use alone will prevent mysql attacks and unauthorized access to the database in all circumstances. For numeric columns, mysql_real_escape_string is not enough. example: $user=mysql_real_escape_string($_GET['user']); $pass=mysql_real_escape_string($_GET['pass']); $id=mysql_real_escape_string($_GET['id']); $query="SELECT x FROM t WHERE user='$user' AND pass='$pass' id=$id"; mysql_query("query); is susceptible to the attack http:example.com/index.php?id=1 OR 1=1 because mysql_real_escape_string does not escape whitespace. The check is_numeric($id) is a solution to the above, putting the number between quotes in the query also is, and using sprintf is another solution, but the documentation does not suggest any of those should be used. There should be at least a pointer to: http://php.net/manual/en/security.database.sql-injection.php so that we newbies know this is not a trivial issue. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=46011&edit=1

« previous php.doc.bugs (#1179) next »