php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #54041 mysql_real_escape_string
Submitted: 2011-02-18 02:56 UTC Modified: 2011-02-20 23:42 UTC
From: chris dot allen dot aaker at gmail dot com Assigned: dtajchreber (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3.5 OS:
Private report: No CVE-ID: None
 [2011-02-18 02:56 UTC] chris dot allen dot aaker at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.mysql-real-escape-string
---
When I run the second example that is suppose to emulate an sql injection attack I don't get anything malevolent looking.

The output is

select * FROM users WHERE users='' and pasword=''.



Test script:
---------------
<?php
// Query database to check if there are any matching users
$query = "SELECT * FROM users WHERE user='{$_POST['username']}' AND password='{$_POST['password']}'";
mysql_query($query);

// We didn't check $_POST['password'], it could be anything the user wanted! For example:
$_POST['username'] = 'aidan';
$_POST['password'] = "' OR ''='";

// This means the query sent to MySQL would be:
echo $query;
?>

Expected result:
----------------
Something malevelent that would allow access with out a valid username/password combination.

Actual result:
--------------
select * FROM users WHERE users='' and pasword=''.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-02-20 23:41 UTC] dtajchreber@php.net
Automatic comment from SVN on behalf of dtajchreber
Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=308511
Log: bug #54041 - http post vars are set before processing. changed order to make example give shown output
 [2011-02-20 23:42 UTC] dtajchreber@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: dtajchreber
 [2011-02-20 23:42 UTC] dtajchreber@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 11:00:02 2026 UTC