Re: Sql Object Model Parser & Sanitizer (was [RFC] is_literal)
| From: | Kamil Tekiela | Date: | Tue, 22 Jun 2021 17:22:59 +0000 |
| Subject: | Re: Sql Object Model Parser & Sanitizer (was [RFC] is_literal) | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-115036@lists.php.net to get a copy of this message | ||
This is open to SQL injection:
$queryBuilder
->select(...$_GET['columns'])
->from($_GET['table'])
->where($_GET['where'])
;
All below statements produce 42. This is valid SQL:
SELECT
42 FROM TABLE() FROM dual;
SELECT ⠀ FROM ⠀;
SELECT * FROM "42"; -- With ANSI_QUOTES
SELECT * FROM """""";
This is valid in MySQL:
VALUES ROW(42)
This is valid in MariaDB:
VALUES (42);
This is not a valid SQL:
SELECT * FROM "\"\"";
There are also windows functions, CTE, Stored procedures, and a bunch of
new features.