#47943 [NEW]: PDO Prepare Documentation
| From: | admin at wdfa dot co dot uk | Date: | Fri, 10 Apr 2009 04:53:18 +0000 |
| Subject: | #47943 [NEW]: PDO Prepare Documentation | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-2092@lists.php.net to get a copy of this message | ||
From: admin at wdfa dot co dot uk
Operating system: na
PHP version: Irrelevant
PHP Bug Type: Documentation problem
Bug description: PDO Prepare Documentation
Description:
------------
Hi,
Can you add more information about the SQL injection prevention properties
of the PDO::Prepare functions. See my notes below.
Regards
Rowan
Reproduce code:
---------------
---
From manual page: pdo.prepare
---
Note on the SQL injection properties of prepared statements.
Prepared statements only project you from SQL injection IF you use the
bindParam or bindValue option.
For example if you have a table called users with two fields, username and
email and someone updates their username you might run
UPDATE
users SET user='$var'
where $var would be the user submitted text.
Now if you did
<?php
$a=new PDO("mysql:host=localhost;dbname=database;","root","");
$b=$a->prepare("UPDATE users SET user='$var'");
$b->execute();
?>
and the user had entered User', email='test for a test the injection
would occur and the email would be updated to test as well as the user
being updated to User.
Using bindParam as follows
<?php
$var="User', email='test";
$a=new PDO("mysql:host=localhost;dbname=database;","root","");
$b=$a->prepare("UPDATE users SET user=:var");
$b->bindParam(":var",$var);
$b->execute();
?>
The sql would be escaped and update the username to User', email='test'
--
Edit bug report at http://bugs.php.net/?id=47943&edit=1
--
Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=47943&r=trysnapshot52
Try a CVS snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=47943&r=trysnapshot53
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=47943&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=47943&r=fixedcvs
Fixed in CVS and need be documented: http://bugs.php.net/fix.php?id=47943&r=needdocs
Fixed in release: http://bugs.php.net/fix.php?id=47943&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=47943&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=47943&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=47943&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=47943&r=support
Expected behavior: http://bugs.php.net/fix.php?id=47943&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=47943&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=47943&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=47943&r=globals
PHP 4 support discontinued: http://bugs.php.net/fix.php?id=47943&r=php4
Daylight Savings: http://bugs.php.net/fix.php?id=47943&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=47943&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=47943&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=47943&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=47943&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=47943&r=mysqlcfg