#47943 [NEW]: PDO Prepare Documentation

From: Date: Fri, 10 Apr 2009 04:53:18 +0000
Subject: #47943 [NEW]: PDO Prepare Documentation
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2092@lists.php.net to get a copy of this message
From: admin at wdfa dot co dot uk Operating system: na PHP version: Irrelevant PHP Bug Type: Documentation problem Bug description: PDO Prepare Documentation Description: ------------ Hi, Can you add more information about the SQL injection prevention properties of the PDO::Prepare functions. See my notes below. Regards Rowan Reproduce code: --------------- --- From manual page: pdo.prepare --- Note on the SQL injection properties of prepared statements. Prepared statements only project you from SQL injection IF you use the bindParam or bindValue option. For example if you have a table called users with two fields, username and email and someone updates their username you might run UPDATE users SET user='$var' where $var would be the user submitted text. Now if you did <?php $a=new PDO("mysql:host=localhost;dbname=database;","root",""); $b=$a->prepare("UPDATE users SET user='$var'"); $b->execute(); ?> and the user had entered User', email='test for a test the injection would occur and the email would be updated to test as well as the user being updated to User. Using bindParam as follows <?php $var="User', email='test"; $a=new PDO("mysql:host=localhost;dbname=database;","root",""); $b=$a->prepare("UPDATE users SET user=:var"); $b->bindParam(":var",$var); $b->execute(); ?> The sql would be escaped and update the username to User', email='test' -- Edit bug report at http://bugs.php.net/?id=47943&edit=1 -- Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=47943&r=trysnapshot52 Try a CVS snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=47943&r=trysnapshot53 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=47943&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=47943&r=fixedcvs Fixed in CVS and need be documented: http://bugs.php.net/fix.php?id=47943&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=47943&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=47943&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=47943&r=needscript Try newer version: http://bugs.php.net/fix.php?id=47943&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=47943&r=support Expected behavior: http://bugs.php.net/fix.php?id=47943&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=47943&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=47943&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=47943&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=47943&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=47943&r=dst IIS Stability: http://bugs.php.net/fix.php?id=47943&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=47943&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=47943&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=47943&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=47943&r=mysqlcfg

« previous php.doc.bugs (#2092) next »