summaryrefslogtreecommitdiff
path: root/tests/sql/mysqli_comment_sqlstyle_fail.phpt
diff options
context:
space:
mode:
authorBen Fuhrmannek2014-07-14 13:07:38 +0200
committerBen Fuhrmannek2014-07-14 13:07:38 +0200
commit1dc59e48642c98e34320f1a31c120fbf290fd509 (patch)
tree5126791aac0c7655daa502a00a53d4c2257ced43 /tests/sql/mysqli_comment_sqlstyle_fail.phpt
parent940509ed02db713920612b0994a57d6227c3655c (diff)
parentaafe0cf82f5fb7220ac6f674bbc1c2091a6a9c4d (diff)
Merge branch 'sql'
Diffstat (limited to 'tests/sql/mysqli_comment_sqlstyle_fail.phpt')
-rw-r--r--tests/sql/mysqli_comment_sqlstyle_fail.phpt25
1 files changed, 25 insertions, 0 deletions
diff --git a/tests/sql/mysqli_comment_sqlstyle_fail.phpt b/tests/sql/mysqli_comment_sqlstyle_fail.phpt
new file mode 100644
index 0000000..83e63c5
--- /dev/null
+++ b/tests/sql/mysqli_comment_sqlstyle_fail.phpt
@@ -0,0 +1,25 @@
1--TEST--
2Mysqli query with SQL comment (--) protection set to fail
3--INI--
4extension=mysqli.so
5suhosin.sql.bailout_on_error=0
6suhosin.sql.comment=2
7suhosin.sql.opencomment=0
8suhosin.sql.multiselect=0
9suhosin.sql.union=0
10suhosin.log.stdout=32
11--SKIPIF--
12<?php
13include('skipifmysqli.inc');
14include('skipif.inc');
15?>
16--FILE--
17<?php
18include('connect.inc');
19$mysqli = connect_mysqli_oostyle();
20$result = $mysqli->query("SELECT 1 -- injection");
21flush();
22echo "mark.";
23?>
24--EXPECTREGEX--
25ALERT - Comment in SQL query.*\) \ No newline at end of file