Doc #63118 [NEW]: mysql_real_escape_string doesn't always prepend backslashes

From: Date: Wed, 19 Sep 2012 16:39:37 +0000
Subject: Doc #63118 [NEW]: mysql_real_escape_string doesn't always prepend backslashes
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8861@lists.php.net to get a copy of this message
From: mark at zedwood dot com Operating system: PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:mysql_real_escape_string doesn't always prepend backslashes Description: ------------ On: http://us3.php.net/manual/en/function.mysql-real-escape-string.php The documentation says: "mysql_real_escape_string() calls MySQL's library function mysql_real_escape_string, which prepends backslashes to the following characters: \x00, \n, \r, \, ', " and \x1a." This implies that "\x00" (1 char) escapes to "\\x00" (4 chars). This is not accurate, it should say "which escapes the following characters", because there are 2 cases where it doesn't just prepend a slash. For null and CTRL-Z, it turns "\x00" into '\0' and "\x1a" into '\Z'. If it didn't, it would be vulnerable to buffer overflow. The mysql C API documentation says, to allocate a buffer of input_length*2+1, implying that each escaped char can only ever escape to a max of 2 chars. http://dev.mysql.com/doc/refman/4.1/en/mysql-real-escape-string.html Test script: --------------- $db = mysql_connect($host, $user, $pass) or die("err: " . mysql_error()); mysql_select_db($dbname, $db) or die("err: " . mysql_error()); $a = mysql_real_escape_string("\x00\n\r\"'\x1a"); echo $a; Expected result: ---------------- //expected, based on current documentation: \x00\n\r\"\'\x1a Actual result: -------------- //actual: \0\n\r\"\'\Z -- Edit bug report at https://bugs.php.net/bug.php?id=63118&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=63118&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=63118&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=63118&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=63118&r=fixed Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=63118&r=needdocs Fixed in release: https://bugs.php.net/fix.php?id=63118&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=63118&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=63118&r=needscript Try newer version: https://bugs.php.net/fix.php?id=63118&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=63118&r=support Expected behavior: https://bugs.php.net/fix.php?id=63118&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=63118&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=63118&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=63118&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=63118&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=63118&r=dst IIS Stability: https://bugs.php.net/fix.php?id=63118&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=63118&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=63118&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=63118&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=63118&r=mysqlcfg

« previous php.doc.bugs (#8861) next »