#46011 [Opn->WFx]: mysql_real_escape_string is no protection for numeric fields
| From: | danbrown@php.net | Date: | Sun, 02 Nov 2008 17:16:59 +0000 |
| Subject: | #46011 [Opn->WFx]: mysql_real_escape_string is no protection for numeric fields | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-1293@lists.php.net to get a copy of this message | ||
ID: 46011
Updated by: danbrown@php.net
Reported By: pablo dot angulo at uam dot es
-Status: Open
+Status: Wont fix
Bug Type: Documentation problem
Operating System: Irrelevant
PHP Version: Irrelevant
New Comment:
There are articles and places for that, including the user notes. The
purpose and scope of the official manual is to explain the functions on
the function pages. It's neither prudent nor reasonable to try to
explain every facet and risk of every function, and the benefit to the
reader would be outshined by the bloat of the documentation.
Previous Comments:
------------------------------------------------------------------------
[2008-09-30 10:26:10] pablo dot angulo at uam dot es
"http://php.net/manual/en/function.mysql-query.php
should really
contain a warning about SQL injection."
absolutely agree
"Even better, mysql_query should be deprecated and replaced by a
safe(r) variant."
That may be too radical, as there are CMS that rely on this function
and provide (I hope) safety wrappers around mysql calls. Also, many
times there is no user input in a mysql call.
------------------------------------------------------------------------
[2008-09-30 09:20:46] olafvdspek at gmail dot com
http://php.net/manual/en/function.mysql-query.php
should really contain
a warning about SQL injection.
Even better, mysql_query should be deprecated and replaced by a safe(r)
variant.
------------------------------------------------------------------------
[2008-09-06 17:34:26] pablo dot angulo at uam dot es
Description:
------------
mysql_real_escape_string documentation gives the false impression that
its use alone will prevent mysql attacks and unauthorized access to the
database in all circumstances.
For numeric columns, mysql_real_escape_string is not enough.
example:
$user=mysql_real_escape_string($_GET['user']);
$pass=mysql_real_escape_string($_GET['pass']);
$id=mysql_real_escape_string($_GET['id']);
$query="SELECT x FROM t WHERE user='$user' AND pass='$pass' id=$id";
mysql_query("query);
is susceptible to the attack
http:example.com/index.php?id=1 OR 1=1
because mysql_real_escape_string does not escape whitespace.
The check is_numeric($id) is a solution to the above, putting the
number between quotes in the query also is, and using sprintf is another
solution, but the documentation does not suggest any of those should be
used. There should be at least a pointer to:
http://php.net/manual/en/security.database.sql-injection.php
so that we newbies know this is not a trivial issue.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=46011&edit=1