RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!
| From: | Andrew Hill | Date: | Mon, 11 Feb 2002 14:33:53 +0000 |
| Subject: | RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-84273@lists.php.net to get a copy of this message | ||
> I understand you try to 'protect' your own product, but you have to
> stay a bit realistic about some things. Ofcourse I check the input.
> But you know... there's absolutely nothing wrong with allowing
> quotes to be stored in the database. It's just that awful 'feature'
> that makes it rather dangerous to do. If that feature/bug was
> documented _anywhere_ it would still not be good, but at least
> someone would know that PHP does this. But no... it's not
> documented, not anywhere! You can't check user input on stuff you
> don't know it can harm anything. Like I said... quotes are very
> normal to be allowed in the database.
>
> It would be a good thing if you guys do something of:
>
> 1. Good rid of the bug(/feature) right a way or
> 2. Document it clearly. Eg. in the documentation of odbc_execute().
>
I'll echo Lars that you should always validate data, whether or not you
assume it to be safe.
That being said, if '/etc/passwd' is readable by your webserver you've got
bigger problems.
Best regards,
Andrew Hill
Director of Technology Evangelism
http://www.openlinksw.com/virtuoso/whatis.htm
OpenLink Virtuoso Internet Data Integration Server