File: null_byte_2.phpt

package info (click to toggle)
php5 5.6.7%2Bdfsg-1
  • links: PTS, VCS
  • area: main
  • in suites: jessie-kfreebsd
  • size: 150,376 kB
  • sloc: ansic: 727,510; php: 21,966; sh: 12,356; cpp: 8,763; xml: 6,105; yacc: 1,551; exp: 1,514; makefile: 1,461; pascal: 1,048; awk: 538; perl: 315; sql: 22
file content (50 lines) | stat: -rw-r--r-- 1,008 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
--TEST--
Null bytes in SQL statements
--SKIPIF--
<?php
$target_dbs = array('oracledb' => true, 'timesten' => false);  // test runs on these DBs
require(dirname(__FILE__).'/skipif.inc');
?> 
--INI--
display_errors = On
error_reporting = E_WARNING
--FILE--
<?php

require(dirname(__FILE__).'/connect.inc');

// Run Test

echo "Test 1: Valid use of a null byte\n";

$s = oci_parse($c, "select * \0from dual");
oci_execute($s);
oci_fetch_all($s, $res);
var_dump($res);

echo "Test 3: Using a null byte in a bind variable name\n";

$s = oci_parse($c, "select * from dual where :bv = 1");
$bv = 1;
oci_bind_by_name($s, ":bv\0:bv", $bv);
oci_execute($s);
 

?>
===DONE===
<?php exit(0); ?>
--EXPECTF--
Test 1: Valid use of a null byte
array(1) {
  ["DUMMY"]=>
  array(1) {
    [0]=>
    string(1) "X"
  }
}
Test 3: Using a null byte in a bind variable name

Warning: oci_bind_by_name(): ORA-01036: %s in %snull_byte_2.php on line %d

Warning: oci_execute(): ORA-01008: %s in %snull_byte_2.php on line %d
===DONE===