#47943 [Opn->Csd]: PDO Prepare Documentation
| From: | vrana@php.net | Date: | Thu, 19 Nov 2009 10:56:59 +0000 |
| Subject: | #47943 [Opn->Csd]: PDO Prepare Documentation | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3228@lists.php.net to get a copy of this message | ||
ID: 47943
Updated by: vrana@php.net
Reported By: admin at wdfa dot co dot uk
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: na
PHP Version: Irrelevant
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2009-11-19 10:56:58] svn@php.net
Automatic comment from SVN on behalf of vrana
Revision: http://svn.php.net/viewvc/?view=revision&revision=290976
Log: Safety note (bug #47943)
------------------------------------------------------------------------
[2009-04-10 04:53:17] admin at wdfa dot co dot uk
Description:
------------
Hi,
Can you add more information about the SQL injection prevention
properties of the PDO::Prepare functions. See my notes below.
Regards
Rowan
Reproduce code:
---------------
---
From manual page: pdo.prepare
---
Note on the SQL injection properties of prepared statements.
Prepared statements only project you from SQL injection IF you use the
bindParam or bindValue option.
For example if you have a table called users with two fields, username
and email and someone updates their username you might run
UPDATE
users SET user='$var'
where $var would be the user submitted text.
Now if you did
<?php
$a=new PDO("mysql:host=localhost;dbname=database;","root","");
$b=$a->prepare("UPDATE users SET user='$var'");
$b->execute();
?>
and the user had entered User', email='test for a test the injection
would occur and the email would be updated to test as well as the user
being updated to User.
Using bindParam as follows
<?php
$var="User', email='test";
$a=new PDO("mysql:host=localhost;dbname=database;","root","");
$b=$a->prepare("UPDATE users SET user=:var");
$b->bindParam(":var",$var);
$b->execute();
?>
The sql would be escaped and update the username to User', email='test'
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47943&edit=1