|
| 1 | +--TEST-- |
| 2 | +mysqli_quote_string() |
| 3 | +--EXTENSIONS-- |
| 4 | +mysqli |
| 5 | +--SKIPIF-- |
| 6 | +<?php |
| 7 | +require_once 'skipifconnectfailure.inc'; |
| 8 | +?> |
| 9 | +--FILE-- |
| 10 | +<?php |
| 11 | + |
| 12 | +require_once 'connect.inc'; |
| 13 | +mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT); |
| 14 | +$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket); |
| 15 | + |
| 16 | +echo mysqli_quote_string($link, '\\') . "\n"; |
| 17 | +echo mysqli_quote_string($link, '"') . "\n"; |
| 18 | +echo mysqli_quote_string($link, "'") . "\n"; |
| 19 | + |
| 20 | +$escaped = mysqli_quote_string($link, "\' \ \""); |
| 21 | +echo $escaped . "\n"; |
| 22 | +$result = $link->query("SELECT $escaped AS test"); |
| 23 | +$value = $result->fetch_column(); |
| 24 | +echo $value . "\n"; |
| 25 | + |
| 26 | +$escaped = mysqli_quote_string($link, '" OR 1=1 -- foo'); |
| 27 | +echo $escaped . "\n"; |
| 28 | +$result = $link->query("SELECT $escaped AS test"); |
| 29 | +$value = $result->fetch_column(); |
| 30 | +echo $value . "\n"; |
| 31 | + |
| 32 | +$escaped = mysqli_quote_string($link, "\n"); |
| 33 | +if ($escaped !== "'\\n'") { |
| 34 | + printf("[001] Expected '\\n', got %s\n", $escaped); |
| 35 | +} |
| 36 | + |
| 37 | +$escaped = mysqli_quote_string($link, "\r"); |
| 38 | +if ($escaped !== "'\\r'") { |
| 39 | + printf("[002] Expected '\\r', got %s\n", $escaped); |
| 40 | +} |
| 41 | + |
| 42 | +$escaped = mysqli_quote_string($link, "foo" . chr(0) . "bar"); |
| 43 | +if ($escaped !== "'foo\\0bar'") { |
| 44 | + printf("[003] Expected 'foo\\0bar', got %s\n", $escaped); |
| 45 | +} |
| 46 | + |
| 47 | +echo "=====================\n"; |
| 48 | + |
| 49 | +// Test that the SQL injection is impossible with NO_BACKSLASH_ESCAPES mode |
| 50 | +$link->query('SET @@sql_mode="NO_BACKSLASH_ESCAPES"'); |
| 51 | + |
| 52 | +echo $link->quote_string('\\') . "\n"; |
| 53 | +echo $link->quote_string('"') . "\n"; |
| 54 | +echo $link->quote_string("'") . "\n"; |
| 55 | + |
| 56 | +$escaped = $link->quote_string("\' \ \""); |
| 57 | +echo $escaped . "\n"; |
| 58 | +$result = $link->query("SELECT $escaped AS test"); |
| 59 | +$value = $result->fetch_column(); |
| 60 | +echo $value . "\n"; |
| 61 | + |
| 62 | +$escaped = $link->quote_string('" OR 1=1 -- foo'); |
| 63 | +echo $escaped . "\n"; |
| 64 | +$result = $link->query("SELECT $escaped AS test"); |
| 65 | +$value = $result->fetch_column(); |
| 66 | +echo $value . "\n"; |
| 67 | + |
| 68 | +echo "done!"; |
| 69 | +?> |
| 70 | +--EXPECT-- |
| 71 | +'\\' |
| 72 | +'\"' |
| 73 | +'\'' |
| 74 | +'\\\' \\ \"' |
| 75 | +\' \ " |
| 76 | +'\" OR 1=1 -- foo' |
| 77 | +" OR 1=1 -- foo |
| 78 | +===================== |
| 79 | +'\' |
| 80 | +'"' |
| 81 | +'''' |
| 82 | +'\'' \ "' |
| 83 | +\' \ " |
| 84 | +'" OR 1=1 -- foo' |
| 85 | +" OR 1=1 -- foo |
| 86 | +done! |
0 commit comments