{"id":7457028,"date":"2016-06-07T23:09:45","date_gmt":"2016-06-07T23:09:45","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/encoding-issue-causing-php-error-and-sql-injection\/"},"modified":"2016-08-31T18:52:47","modified_gmt":"2016-08-31T18:52:47","slug":"encoding-issue-causing-php-error-and-sql-injection","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/encoding-issue-causing-php-error-and-sql-injection\/","title":{"rendered":"Encoding Issue causing PHP Error and SQL Injection"},"content":{"rendered":"<p>Certain search strings are not being encoded\/decoded by the plugin correctly and are thus:<\/p>\n<p>1. Causing the WP_Query SQL string to break, resulting in a WordPress Database error, and<br \/>\n2. Exposing a SQL injection vulnerability. It is currently possible to use certain character combinations to inject a single apostrophe (see below). Ack!<\/p>\n<p>An example search parameter that causes this is:<br \/>\n<code>\/?s=A+%5C%27<\/code><\/p>\n<p>Resulting in error:<\/p>\n<pre><code>WordPress database error: [You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near &#039;%&#039;)) OR (((m.meta_value LIKE &#039;%A%&#039;) AND (m.meta_value LIKE &#039;%%&#039;)) OR (m.meta_va&#039; at line 1]\nSELECT DISTINCT SQL_CALC_FOUND_ROWS wp_posts.* FROM wp_posts LEFT JOIN wp_term_relationships AS trel ON (wp_posts.ID = trel.object_id) LEFT JOIN wp_term_taxonomy AS ttax ON ( ( ttax.taxonomy = &#039;category&#039; OR ttax.taxonomy = &#039;post_format&#039; OR ttax.taxonomy = &#039;action-group&#039; OR ttax.taxonomy = &#039;product_type&#039; OR ttax.taxonomy = &#039;product_cat&#039; OR ttax.taxonomy = &#039;product_tag&#039; OR ttax.taxonomy = &#039;product_shipping_class&#039; OR ttax.taxonomy = &#039;tribe_events_cat&#039; OR ttax.taxonomy = &#039;issue_date&#039; OR ttax.taxonomy = &#039;project_type&#039; OR ttax.taxonomy = &#039;project_site&#039; ) AND trel.term_taxonomy_id = ttax.term_taxonomy_id) LEFT JOIN wp_terms AS tter ON (ttax.term_id = tter.term_id) LEFT JOIN wp_postmeta AS m ON (wp_posts.ID = m.post_id) LEFT JOIN wp_users AS u ON (wp_posts.post_author = u.ID) WHERE 1=1 AND ( ( (((((wp_posts.post_title LIKE &#039;%A%&#039;) OR (wp_posts.post_content LIKE &#039;%A%&#039;)) AND ((wp_posts.post_title LIKE &#039;%%&#039;) OR (wp_posts.post_content LIKE &#039;%%&#039;))) OR (((tter.slug LIKE &#039;%a%&#039;) AND (tter.slug LIKE &#039;%%&#039;)) OR (tter.slug LIKE &#039;%a%&#039;)) OR (((ttax.description LIKE &#039;%A%&#039;) AND (ttax.description LIKE &#039;%%&#039;)) OR (ttax.description LIKE &#039;%A \\\\&#039;%&#039;)) OR (((m.meta_value LIKE &#039;%A%&#039;) AND (m.meta_value LIKE &#039;%%&#039;)) OR (m.meta_value LIKE &#039;%A \\\\&#039;%&#039;)) OR (((wp_posts.post_excerpt LIKE &#039;%A%&#039;) AND (wp_posts.post_excerpt LIKE &#039;%%&#039;)) OR (wp_posts.post_excerpt LIKE &#039;%A \\\\&#039;%&#039;)) OR ((u.display_name LIKE &#039;%A%&#039;) OR (u.display_name LIKE &#039;%%&#039;) OR (u.display_name LIKE &#039;%A \\\\&#039;%&#039;)) )) AND wp_posts.post_type IN (&#039;post&#039;, &#039;page&#039;, &#039;attachment&#039;, &#039;nf_sub&#039;, &#039;product&#039;, &#039;wbeexportfile&#039;, &#039;tribe_events&#039;, &#039;tribe_venue&#039;, &#039;programs&#039;, &#039;resources&#039;, &#039;preservationinprint&#039;, &#039;projects&#039;) AND (wp_posts.post_status = &#039;publish&#039; OR wp_posts.post_status = &#039;acf-disabled&#039; OR wp_posts.post_author = 1 AND wp_posts.post_status = &#039;private&#039;)) AND post_type != &#039;revision&#039;) AND post_status != &#039;future&#039; ORDER BY (CASE WHEN wp_posts.post_title LIKE &#039;%A \\\\\\\\\\&#039;%&#039; THEN 1 WHEN wp_posts.post_title LIKE &#039;%\\\\\\\\%&#039; THEN 2 WHEN wp_posts.post_excerpt LIKE &#039;%A \\\\\\\\\\&#039;%&#039; THEN 4 WHEN wp_posts.post_content LIKE &#039;%A \\\\\\\\\\&#039;%&#039; THEN 5 ELSE 6 END), wp_posts.post_date DESC LIMIT 0, 12<\/code><\/pre>\n<p>I have to disable the plugin and urge everyone else to disable this plugin until the vulnerability has been fixed. Please contact me when this has been patched.<\/p>\n<p>Thank you!<\/p>\n<p>https:\/\/wordpress.org\/plugins\/search-everything\/<\/p>\n","protected":false},"template":"","class_list":["post-7457028","topic","type-topic","status-publish","hentry","topic-tag-decoding","topic-tag-encoding","topic-tag-sql","topic-tag-sql-injection","topic-tag-wordpress-database-error"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/7457028","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/7457028\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=7457028"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}