Doc #54041 [NEW]: mysql_real_escape_string

From: Date: Fri, 18 Feb 2011 01:56:19 +0000
Subject: Doc #54041 [NEW]: mysql_real_escape_string
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-6006@lists.php.net to get a copy of this message
From: Operating system: PHP version: 5.3.5 Package: Documentation problem Bug Type: Documentation Problem Bug description:mysql_real_escape_string Description: ------------ --- From manual page: http://www.php.net/function.mysql-real-escape-string --- When I run the second example that is suppose to emulate an sql injection attack I don't get anything malevolent looking. The output is select * FROM users WHERE users='' and pasword=''. Test script: --------------- <?php // Query database to check if there are any matching users $query = "SELECT * FROM users WHERE user='{$_POST['username']}' AND password='{$_POST['password']}'"; mysql_query($query); // We didn't check $_POST['password'], it could be anything the user wanted! For example: $_POST['username'] = 'aidan'; $_POST['password'] = "' OR ''='"; // This means the query sent to MySQL would be: echo $query; ?> Expected result: ---------------- Something malevelent that would allow access with out a valid username/password combination. Actual result: -------------- select * FROM users WHERE users='' and pasword=''. -- Edit bug report at http://bugs.php.net/bug.php?id=54041&edit=1 -- Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=54041&r=trysnapshot52 Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=54041&r=trysnapshot53 Try a snapshot (trunk): http://bugs.php.net/fix.php?id=54041&r=trysnapshottrunk Fixed in SVN: http://bugs.php.net/fix.php?id=54041&r=fixed Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=54041&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=54041&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=54041&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=54041&r=needscript Try newer version: http://bugs.php.net/fix.php?id=54041&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=54041&r=support Expected behavior: http://bugs.php.net/fix.php?id=54041&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=54041&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=54041&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=54041&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=54041&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=54041&r=dst IIS Stability: http://bugs.php.net/fix.php?id=54041&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=54041&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=54041&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=54041&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=54041&r=mysqlcfg

« previous php.doc.bugs (#6006) next »