Doc #54041 [Opn->Csd]: mysql_real_escape_string

From: Date: Sun, 20 Feb 2011 22:42:55 +0000
Subject: Doc #54041 [Opn->Csd]: mysql_real_escape_string
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-6008@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=54041&edit=1 ID: 54041 Updated by: dtajchreber@php.net Reported by: chris dot allen dot aaker at gmail dot com Summary: mysql_real_escape_string -Status: Open +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: 5.3.5 -Assigned To: +Assigned To: dtajchreber Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2011-02-20 23:41:19] dtajchreber@php.net Automatic comment from SVN on behalf of dtajchreber Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=308511 Log: bug #54041 - http post vars are set before processing. changed order to make example give shown output ------------------------------------------------------------------------ [2011-02-18 02:56:18] chris dot allen dot aaker at gmail dot com Description: ------------ --- From manual page: http://www.php.net/function.mysql-real-escape-string --- When I run the second example that is suppose to emulate an sql injection attack I don't get anything malevolent looking. The output is select * FROM users WHERE users='' and pasword=''. Test script: --------------- <?php // Query database to check if there are any matching users $query = "SELECT * FROM users WHERE user='{$_POST['username']}' AND password='{$_POST['password']}'"; mysql_query($query); // We didn't check $_POST['password'], it could be anything the user wanted! For example: $_POST['username'] = 'aidan'; $_POST['password'] = "' OR ''='"; // This means the query sent to MySQL would be: echo $query; ?> Expected result: ---------------- Something malevelent that would allow access with out a valid username/password combination. Actual result: -------------- select * FROM users WHERE users='' and pasword=''. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=54041&edit=1

« previous php.doc.bugs (#6008) next »