#47943 [Opn->Csd]: PDO Prepare Documentation

From: Date: Thu, 19 Nov 2009 10:56:59 +0000
Subject: #47943 [Opn->Csd]: PDO Prepare Documentation
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3228@lists.php.net to get a copy of this message
ID: 47943 Updated by: vrana@php.net Reported By: admin at wdfa dot co dot uk -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: na PHP Version: Irrelevant New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2009-11-19 10:56:58] svn@php.net Automatic comment from SVN on behalf of vrana Revision: http://svn.php.net/viewvc/?view=revision&revision=290976 Log: Safety note (bug #47943) ------------------------------------------------------------------------ [2009-04-10 04:53:17] admin at wdfa dot co dot uk Description: ------------ Hi, Can you add more information about the SQL injection prevention properties of the PDO::Prepare functions. See my notes below. Regards Rowan Reproduce code: --------------- --- From manual page: pdo.prepare --- Note on the SQL injection properties of prepared statements. Prepared statements only project you from SQL injection IF you use the bindParam or bindValue option. For example if you have a table called users with two fields, username and email and someone updates their username you might run UPDATE users SET user='$var' where $var would be the user submitted text. Now if you did <?php $a=new PDO("mysql:host=localhost;dbname=database;","root",""); $b=$a->prepare("UPDATE users SET user='$var'"); $b->execute(); ?> and the user had entered User', email='test for a test the injection would occur and the email would be updated to test as well as the user being updated to User. Using bindParam as follows <?php $var="User', email='test"; $a=new PDO("mysql:host=localhost;dbname=database;","root",""); $b=$a->prepare("UPDATE users SET user=:var"); $b->bindParam(":var",$var); $b->execute(); ?> The sql would be escaped and update the username to User', email='test' ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=47943&edit=1

« previous php.doc.bugs (#3228) next »