php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #24651 PHP is not dealing properly with variable names ending in 'id'
Submitted: 2003-07-14 15:59 UTC Modified: 2003-07-14 17:54 UTC
From: mikea at gb-im dot com Assigned:
Status: Closed Package: Variables related
PHP Version: 4.3.1 OS: Linux Slackware 9.0
Private report: No CVE-ID: None
View Add Comment Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
You can add a comment by following this link or if you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: mikea at gb-im dot com
New email:
PHP Version: OS:

 

 [2003-07-14 15:59 UTC] mikea at gb-im dot com
Description:
------------
RE: bug 15052

We are having a similar problem with scripts that were working fine in older versions of PHP (4.16, etc.) and now that we are on version 4.3.1, any variable that I have that ends in the letters 'id' isn't being passed properly from POST submissions to form handler scripts. NO CODE HAS CHANGES IN THE SCRIPTS THEMSELVES, ONLY THE VERSION OF PHP HAS CHANGED.

For example:

A snipet from the form (I switched normal HTML brackets for square brackets for readibility and posible security issues on this bug tracker):

[form method="post" action="form_submit.php?ul=$ul&uid=$uid"]

COMMENT: the URL variables of UL and UID are pulled from values passed in on th calling link and represent user level and user ID respectively. I have no problem retrieving these values.

[select name="sid"]
[option value="NOTUSED"]NOTUSED[/option]
[option value=1]blah[/option]
[option value=2]rocco[/option]
[/select]

[/form]

COMMENT: When the form is submitted, I dynamically create an SQL string based on which form fields are filled out. So, in the receiving script, there is logic similar to this:

If ($sid != 'NOTUSED')
{

   $search_string = $search_string . " and sid = '$sid'";

}

When the script has finished looking at all of the submitted form values, and you look at the finished SQL query string, it ends up looking like this:

"select * from orders where stuff = 'stuff' and junk = 'junk' and sid = '1sid1'";

I honestly have no idea what is going on, a the scripts themselves worked fine under the older versions of PHP and now is doing this. It is a strange error. We temporarily fixed it by exploding the $sid variable. That allowed us to seperate out the first character and isolate it for use throughout the script.

Any thoughts? 

Reproduce code:
---------------
<html>
<body>
<?PHP
$ul = 2;
$uid = 99999;
print "<form method=\"post\" action=\"myform_process.php?ul=$ul&uid=$uid\">";
?>
<select name=sid>
<option>[not used]</option>
<option value=1>blah</option>
<option value=2>stuff</option>
</select>
<input type="submit" value="submit now!">
</form>
</body>
</html>

Expected result:
----------------
A printed statement (assuming I chose the option labeled 'blah'):

select * from orders where uid = '99999' and sid = '1'

Actual result:
--------------
This is the actual printed statement:

select * from orders where uid = '99999' and sid = '1sid=1'

(the form submit-to script looks like this:

<?PHP
print "select * from orders where uid = '$uid' and sid = '$sid'"; 
?>

)

Yes, that is all the script does is print out a statement in this example!

Patches

Add a Patch

Pull Requests

Add a Pull Request

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2003-07-14 17:54 UTC] sniper@php.net
Please try using this CVS snapshot:

  http://snaps.php.net/php4-STABLE-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php4-win32-STABLE-latest.zip

Works fine with latest CVS snapshot.

 
PHP Copyright © 2001-2024 The PHP Group
All rights reserved.
Last updated: Thu Apr 18 17:01:28 2024 UTC