Описание
SQL injection in ext-pgsql via E'...' backslash breakout
php_pgsql_convert() is used to convert and escape user-provided parameters in pg_insert(), pg_update(), pg_select(), and pg_delete(). It does so using PQescapeStringConn() and then wraps the result in an escape string constant, E'...' (via php_pgsql_add_quotes()).
With standard_conforming_strings = on (the default since PostgreSQL 9.1), PQescapeStringConn() does not correctly escape values for the escape string constant E'...', as it does not escape \ under this configuration. When PQescapeStringConn() escapes ' as '', an attacker can trivially terminate the string by escaping the first single quote.
Note that the doubled \\ is a PHP escape sequence and that the \ appears only once in the parameter. Also note that pg_select() escapes the ' by doubling it but does not escape the \. Consequently, the first of the two ' characters is escaped (meaning that it represents a literal '), while the second terminates the string. Everything after that is interpreted as part of the query.
The solution changes php_pgsql_convert() to wrap parameters in non-escaping string constants instead.
Пакеты
php
>=8.2.0, <8.2.33
8.2.33
php
>=8.3.0, <8.3.33
8.3.33
php
>=8.4.0, <8.4.24
8.4.24
php
>=8.5.0, <8.5.9
8.5.9
Связанные уязвимости
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Improper escaping of backslashes in attacker-provided parameters would ...