WordPress.org

Make WordPress Core


Ignore:
Timestamp:
09/19/2017 02:58:49 PM (3 years ago)
Author:
aaroncampbell
Message:

Database: Hardening for wpdb::prepare()

Previously if you passed an array of values for placeholders, additional values could be passed as well. Now additional values will be ignored.

Merges [41470] to 4.7 branch.

Location:
branches/4.7
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • branches/4.7

  • branches/4.7/tests/phpunit/tests/db.php

    r39627 r41472  
    355355    }
    356356
     357    function test_prepare_sprintf() {
     358        global $wpdb;
     359
     360        $prepared = $wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", 1, "admin" );
     361        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 1 AND user_login = 'admin'", $prepared );
     362    }
     363
     364    /**
     365     * @expectedIncorrectUsage wpdb::prepare
     366     */
     367    function test_prepare_sprintf_invalid_args() {
     368        global $wpdb;
     369
     370        $prepared = @$wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", 1, array( "admin" ) );
     371        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 1 AND user_login = ''", $prepared );
     372
     373        $prepared = @$wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", array( 1 ), "admin" );
     374        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 0 AND user_login = 'admin'", $prepared );
     375    }
     376
     377        function test_prepare_vsprintf() {
     378                global $wpdb;
     379
     380        $prepared = $wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", array( 1, "admin" ) );
     381        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 1 AND user_login = 'admin'", $prepared );
     382    }
     383
     384    /**
     385     * @expectedIncorrectUsage wpdb::prepare
     386     */
     387    function test_prepare_vsprintf_invalid_args() {
     388        global $wpdb;
     389
     390        $prepared = @$wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", array( 1, array( "admin" ) ) );
     391        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 1 AND user_login = ''", $prepared );
     392
     393        $prepared = @$wpdb->prepare( "SELECT * FROM $wpdb->users WHERE id = %d AND user_login = %s", array( array( 1 ), "admin" ) );
     394        $this->assertEquals( "SELECT * FROM $wpdb->users WHERE id = 0 AND user_login = 'admin'", $prepared );
     395        }
     396
    357397    function test_db_version() {
    358398        global $wpdb;
Note: See TracChangeset for help on using the changeset viewer.