Re: Sql Object Model Parser & Sanitizer (was [RFC] is_literal)

From: Date: Tue, 22 Jun 2021 17:22:59 +0000
Subject: Re: Sql Object Model Parser & Sanitizer (was [RFC] is_literal)
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-115036@lists.php.net to get a copy of this message
This is open to SQL injection: $queryBuilder ->select(...$_GET['columns']) ->from($_GET['table']) ->where($_GET['where']) ; All below statements produce 42. This is valid SQL: SELECT 42 FROM TABLE() FROM dual; SELECT ⠀ FROM ⠀; SELECT * FROM "42"; -- With ANSI_QUOTES SELECT * FROM """"""; This is valid in MySQL: VALUES ROW(42) This is valid in MariaDB: VALUES (42); This is not a valid SQL: SELECT * FROM "\"\""; There are also windows functions, CTE, Stored procedures, and a bunch of new features.

« previous php.internals (#115036) next »