Doc #63118 [Opn->Wfx]: mysql_real_escape_string doesn't always prepend backslashes
| From: | aharvey@php.net | Date: | Thu, 20 Sep 2012 01:20:19 +0000 |
| Subject: | Doc #63118 [Opn->Wfx]: mysql_real_escape_string doesn't always prepend backslashes | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8862@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63118&edit=1
ID: 63118
Updated by: aharvey@php.net
Reported by: mark at zedwood dot com
Summary: mysql_real_escape_string doesn't always prepend
backslashes
-Status: Open
+Status: Wont fix
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
I think the wording on that is fine: the use of the word "character" is important there.
At any rate, since you don't need to allocate a buffer in PHP, I think the reality is that
mysql_real_escape_string() can basically be treated as a black box regardless (unsafe data goes in,
safe data comes out).
Previous Comments:
------------------------------------------------------------------------
[2012-09-19 16:39:37] mark at zedwood dot com
Description:
------------
On:
http://us3.php.net/manual/en/function.mysql-real-escape-string.php
The documentation says: "mysql_real_escape_string() calls MySQL's library function
mysql_real_escape_string, which prepends backslashes to the following characters: \x00, \n, \r, \,
', " and \x1a."
This implies that "\x00" (1 char) escapes to "\\x00" (4 chars).
This is not accurate, it should say "which escapes the following characters", because
there are 2 cases where it doesn't just prepend a slash. For null and CTRL-Z, it turns
"\x00" into '\0' and "\x1a" into '\Z'. If it didn't,
it would be vulnerable to buffer overflow.
The mysql C API documentation says, to allocate a buffer of input_length*2+1, implying that each
escaped char can only ever escape to a max of 2 chars.
http://dev.mysql.com/doc/refman/4.1/en/mysql-real-escape-string.html
Test script:
---------------
$db = mysql_connect($host, $user, $pass) or die("err: " . mysql_error());
mysql_select_db($dbname, $db) or die("err: " . mysql_error());
$a = mysql_real_escape_string("\x00\n\r\"'\x1a");
echo $a;
Expected result:
----------------
//expected, based on current documentation:
\x00\n\r\"\'\x1a
Actual result:
--------------
//actual:
\0\n\r\"\'\Z
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63118&edit=1