Re: [RFC] Block requests to builtin SQL functions where PHP can prove the call is vulnerable to a potential SQL-injection attack

From: Date: Fri, 07 Aug 2015 01:36:45 +0000
Subject: Re: [RFC] Block requests to builtin SQL functions where PHP can prove the call is vulnerable to a potential SQL-injection attack
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-87674@lists.php.net to get a copy of this message
On Fri, Aug 7, 2015 at 10:29 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Even if there is identifier placeholder, SQL keyword remains. > So to be perfect, you'll need another place holder for SQL keywords. > There is no escaping for SQL keywords and it has to be validation. > e.g. ORDER BY {$_GET['order']} > Oops the last line should be e.g. ORDER BY col {$_GET['order']} BTW, instead of improving PHP, users are better to request "identifier escape API" to DB developers like PQescapeIdentifier() in PostgreSQL's client library. IMO. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#87674) next »