note 39291 added to function.mysql-escape-string

From: Date: Fri, 23 Jan 2004 10:36:12 +0000
Subject: note 39291 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-64059@lists.php.net to get a copy of this message
I can't understand why all mysql functions use the \ character to escape special character in queries. THIS IS NOT SQL STANDARD COMPLIANT! To escape the ' character, the real way is to double the character, so it becomes '' (two '). Same thing for all other characters such as % becomes %%. By the current way, when we use Oracle or MSSQL Server by exemple, the result of this function (also MagicQuote) is an error while doing the query, or worste, the query is not protected. select * from users where name = '$login' and password='$password' With $login = "admin" and $password = "dummy' or 1 = 1 --" the query becomes: select * from users where name = 'admin' and password='dummy\' or 1 = 1 --' And then Oracle or MSSQL Server will run the query without understanding the \' as an escaped ' character, so the query is not protected at all! As a result, the user can logon as "admin" even if he don't know the real password! ---- Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+39291 Delete -- http://master.php.net/manage/user-notes.php?action=delete+39291&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+39291&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#64059) next »