Doc #54041 [Opn->Csd]: mysql_real_escape_string
| From: | dtajchreber@php.net | Date: | Sun, 20 Feb 2011 22:42:55 +0000 |
| Subject: | Doc #54041 [Opn->Csd]: mysql_real_escape_string | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-6008@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54041&edit=1
ID: 54041
Updated by: dtajchreber@php.net
Reported by: chris dot allen dot aaker at gmail dot com
Summary: mysql_real_escape_string
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: 5.3.5
-Assigned To:
+Assigned To: dtajchreber
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2011-02-20 23:41:19] dtajchreber@php.net
Automatic comment from SVN on behalf of dtajchreber
Revision: http://svn.php.net/viewvc/?view=revision&revision=308511
Log: bug #54041 - http post vars are set before processing. changed
order to make example give shown output
------------------------------------------------------------------------
[2011-02-18 02:56:18] chris dot allen dot aaker at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.mysql-real-escape-string
---
When I run the second example that is suppose to emulate an sql
injection attack I don't get anything malevolent looking.
The output is
select * FROM users WHERE users='' and pasword=''.
Test script:
---------------
<?php
// Query database to check if there are any matching users
$query = "SELECT * FROM users WHERE user='{$_POST['username']}' AND
password='{$_POST['password']}'";
mysql_query($query);
// We didn't check $_POST['password'], it could be anything the user
wanted! For example:
$_POST['username'] = 'aidan';
$_POST['password'] = "' OR ''='";
// This means the query sent to MySQL would be:
echo $query;
?>
Expected result:
----------------
Something malevelent that would allow access with out a valid
username/password combination.
Actual result:
--------------
select * FROM users WHERE users='' and pasword=''.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54041&edit=1