* Enano - an open-source CMS capable of wiki functions, Drupal-like sidebar blocks, and everything in between
* Version 1.0 (Banshee)
* Copyright (C) 2006-2007 Dan Fuhry
* This program is Free Software; you can redistribute and/or modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
* This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied
* warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for details.
function db_error_handler($errno, $errstr, $errfile = false, $errline = false, $errcontext = Array() )
if ( !defined('ENANO_DEBUG') )
$e = error_reporting(0);
if ( $e < $errno )
$errtype = 'Notice';
switch ( $errno )
case E_ERROR: case E_USER_ERROR: case E_CORE_ERROR: case E_COMPILE_ERROR: $errtype = 'Error'; break;
case E_WARNING: case E_USER_WARNING: case E_CORE_WARNING: case E_COMPILE_WARNING: $errtype = 'Warning'; break;
$debug = debug_backtrace();
$debug = $debug[2]['file'] . ', line ' . $debug[2]['line'];
echo "<b>$errtype:</b> $errstr<br />Error source:<pre>$debug</pre>";
class mysql {
var $num_queries, $query_backtrace, $latest_result, $latest_query, $_conn, $sql_stack_fields, $sql_stack_values;
var $row = array();
var $rowset = array();
var $errhandler;
function enable_errorhandler()
if ( function_exists('debug_backtrace') )
$this->errhandler = set_error_handler('db_error_handler');
function disable_errorhandler()
if ( $this->errhandler )
function sql_backtrace() {
$qb = explode("\n", $this->query_backtrace);
$bt = '';
//for($i=sizeof($qb)-1;$i>=0;$i--) {
for($i=0;$i<sizeof($qb);$i++) {
$bt .= $qb[$i]."\n";
return $bt;
function ensure_connection()
function _die($t = '') {
if(defined('ENANO_HEADERS_SENT')) {
header('HTTP/1.1 500 Internal Server Error');
$bt = $this->sql_backtrace();
$e = htmlspecialchars(mysql_error());
if($e=='') $e='<none>';
if(defined('ENANO_CONFIG_FETCHED')) die_semicritical('Database error', '<h3>An error occurred during a database query.</h3><p>'.$t.'<br />Error returned by MySQL: '.$e.'<br />SQL Backtrace:</p><pre>'.$bt.'</pre>');
else grinding_halt('Database error', '<h3>An error occurred during a database query.</h3><p>'.$t.'<br />Error returned by MySQL: '.$e.'<br />SQL Backtrace:</p><pre>'.$bt.'</pre>');
function die_json()
$e = addslashes(htmlspecialchars(mysql_error()));
$q = addslashes($this->latest_query);
$t = "{'mode':'error','error':'An error occurred during database query.\nQuery was:\n $q\n\nError returned by MySQL: $e'}";
function get_error($t = '') {
header('HTTP/1.1 500 Internal Server Error');
$bt = $this->sql_backtrace();
$e = htmlspecialchars(mysql_error());
if($e=='') $e='<none>';
$text = '<h3>An error occurred during a database query.</h3><p>'.$t.'<br />Error returned by MySQL: '.$e.'<br />SQL Backtrace:</p><pre>'.$bt.'</pre>';
return $text;
function connect() {
dc_here('dbal: trying to connect....');
unset($crypto_key); // Get this sucker out of memory fast
if(!defined('ENANO_INSTALLED') && !defined('MIDGET_INSTALLED') && !defined('IN_ENANO_INSTALL') )
dc_here('dbal: oops, looks like Enano isn\'t set up. Constants ENANO_INSTALLED, MIDGET_INSTALLED, and IN_ENANO_INSTALL are all undefined.');
header('Location: install.php');
$this->_conn = @mysql_connect($dbhost, $dbuser, $dbpasswd);
unset($dbpasswd); // Security
if(!$this->_conn) { dc_here('dbal: uhoh!<br />'.mysql_error()); grinding_halt('Enano is having a problem', '<p>Error: couldn\'t connect to MySQL.<br />'.mysql_error().'</p>'); }
$this->query_backtrace = '';
$this->num_queries = 0;
dc_here('dbal: we\'re in, selecting database...');
$q = $this->sql_query('USE '.$dbname.';');
if(!$q) $this->_die('The database could not be selected.');
dc_here('dbal: connected to MySQL');
function sql_query($q) {
$this->query_backtrace .= $q."\n";
$this->latest_query = $q;
dc_here('dbal: making SQL query:<br /><tt>'.$q.'</tt>');
if(!$this->_conn) $this->_die('A database connection has not yet been established.');
grinding_halt('SQL Injection attempt', '<p>Enano has caught and prevented an SQL injection attempt. Your IP address has been recorded and the administrator has been notified.</p><p>Query was:</p><pre>'.htmlspecialchars($q).'</pre>');
$r = mysql_query($q, $this->_conn);
$this->latest_result = $r;
return $r;
function sql_unbuffered_query($q) {
$this->query_backtrace .= '(UNBUFFERED) ' . $q."\n";
$this->latest_query = $q;
dc_here('dbal: making SQL query:<br /><tt>'.$q.'</tt>');
if(!$this->_conn) $this->_die('A database connection has not yet been established.');
grinding_halt('SQL Injection attempt', '<p>Enano has caught and prevented an SQL injection attempt. Your IP address has been recorded and the administrator has been notified.</p><p>Query was:</p><pre>'.htmlspecialchars($q).'</pre>');
$r = mysql_unbuffered_query($q, $this->_conn);
$this->latest_result = $r;
return $r;
* Checks a SQL query for possible signs of injection attempts
* @param string $q the query to check
* @return bool true if query passed check, otherwise false
function check_query($q, $debug = false)
if($debug) echo "\$db->check_query(): checking query: ".htmlspecialchars($q).'<br />'."\n";
$sz = strlen($q);
$quotechar = false;
$quotepos = 0;
$prev_is_quote = false;
$just_started = false;
for($i=0;$i<strlen($q);$i++,$c=substr($q, $i, 1))
$next = substr($q, $i+1, 1);
$next2 = substr($q, $i+2, 1);
$prev = substr($q, $i-1, 1);
$prev2 = substr($q, $i-2, 1);
if(isset($c) && in_array($c, Array('"', "'", '`')))
( $quotechar == $c && $quotechar != $next && ( $quotechar != $prev || $just_entered ) && $prev != '\\') ||
( $prev2 == '\\' && $prev == $quotechar && $quotechar == $c )
+ − 198
+ − 199
+ − 200
+ − 201
+ − 202
+ − 203
+ − 207
+ − 208
+ − 209
+ − 210
if($debug) echo '$db->check_query(): found quote char as pos: '.$i.'<br />';
$just_entered = false;
if(substr(trim($q), strlen(trim($q))-1, 1) == ';') $q = substr(trim($q), 0, strlen(trim($q))-1);
for($i=0;$i<strlen($q);$i++,$c=substr($q, $i, 1))
if( ( $c == ';' && $i != $sz-1 ) || $c . substr($q, $i+1, 1) == '--') // Don't permit semicolons in mid-query, and never allow comments
// Injection attempt!
$e = '';
if($j == $i) $e .= '<span style="color: red; text-decoration: underline;">' . $c . '</span>';
else $e .= $c;
echo 'Injection attempt caught at pos: '.$i.'<br />';
return false;
return true;
* Set the internal result pointer to X
* @param int $pos The number of the row
* @param resource $result The MySQL result resource - if not given, the latest cached query is assumed
* @return true on success, false on failure
function sql_data_seek($pos, $result = false)
+ − 248
+ − 250
+ − 253
+ − 255
+ − 256
return true;
return false;
* Reports a bad query to the admin
* @param string $query the naughty query
* @access private
function report_query($query)
global $session;
if(is_object($session) && defined('ENANO_MAINSTREAM'))
+ − 277
+ − 278
$username = 'Unavailable';
$query = $this->escape($query);
$q = $this->sql_query('INSERT INTO '.table_prefix.'logs(log_type, action, time_id, date_string, page_text, author, edit_summary)
VALUES(\'security\', \'sql_inject\', '.time().', \'\', \''.$query.'\', \''.$username.'\', \''.$_SERVER['REMOTE_ADDR'].'\');');
function fetchrow($r = false) {
if(!$this->_conn) return false;
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
$row = mysql_fetch_assoc($r);
return $row;
function fetchrow_num($r = false) {
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
$row = mysql_fetch_row($r);
return $row;
function numrows($r = false) {
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
$n = mysql_num_rows($r);
return $n;
function escape($str)
$str = mysql_real_escape_string($str);
return $str;
function free_result($result = false)
$result = $this->latest_result;
+ − 328
return null;
return null;
function close() {
dc_here('dbal: closing MySQL connection');
// phpBB DBAL compatibility
function sql_fetchrow($r = false)
+ − 345
function sql_freeresult($r = false)
if(!$this->_conn) return false;
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
function sql_numrows($r = false)
if(!$this->_conn) return false;
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
return mysql_num_rows($r);
function sql_affectedrows($r = false, $f, $n)
if(!$this->_conn) return false;
if(!$r) $r = $this->latest_result;
if(!$r) $this->_die('$db->fetchrow(): an invalid MySQL resource was passed.');
return mysql_affected_rows();
+ − 368
function sql_type_cast(&$value)
+ − 372
+ − 374
if ( is_integer($value) || is_bool($value) )
+ − 377
+ − 378
if ( is_string($value) || empty($value) )
+ − 381
+ − 382
// uncastable var : let's do a basic protection on it to prevent sql injection attempt
return '\'' . $this->sql_escape_string(htmlspecialchars($value)) . '\'';
function sql_statement(&$fields, $fields_inc='')
// init result
$this->sql_fields = $this->sql_values = $this->sql_update = '';
if ( empty($fields) && empty($fields_inc) )
+ − 393
+ − 395
// process
if ( !empty($fields) )
$first = true;
foreach ( $fields as $field => $value )
// field must contain a field name
if ( !empty($field) && is_string($field) )
$value = $this->sql_type_cast($value);
$this->sql_fields .= ( $first ? '' : ', ' ) . $field;
$this->sql_values .= ( $first ? '' : ', ' ) . $value;
$this->sql_update .= ( $first ? '' : ', ' ) . $field . ' = ' . $value;
$first = false;
if ( !empty($fields_inc) )
foreach ( $fields_inc as $field => $indent )
if ( $indent != 0 )
$this->sql_update .= (empty($this->sql_update) ? '' : ', ') . $field . ' = ' . $field . ($indent < 0 ? ' - ' : ' + ') . abs($indent);
function sql_stack_reset($id='')
if ( empty($id) )
$this->sql_stack_fields = array();
$this->sql_stack_values = array();
$this->sql_stack_fields[$id] = array();
$this->sql_stack_values[$id] = array();
function sql_stack_statement(&$fields, $id='')
if ( empty($id) )
$this->sql_stack_fields = $this->sql_fields;
$this->sql_stack_values[] = '(' . $this->sql_values . ')';
$this->sql_stack_fields[$id] = $this->sql_fields;
$this->sql_stack_values[$id][] = '(' . $this->sql_values . ')';
function sql_stack_insert($table, $transaction=false, $line='', $file='', $break_on_error=true, $id='')
if ( (empty($id) && empty($this->sql_stack_values)) || (!empty($id) && empty($this->sql_stack_values[$id])) )
return false;
switch( SQL_LAYER )
case 'mysql':
case 'mysql4':
if ( empty($id) )
$sql = 'INSERT INTO ' . $table . '
(' . $this->sql_stack_fields . ') VALUES ' . implode(",\n", $this->sql_stack_values);
$sql = 'INSERT INTO ' . $table . '
(' . $this->sql_stack_fields[$id] . ') VALUES ' . implode(",\n", $this->sql_stack_values[$id]);
return $this->sql_query($sql, $transaction, $line, $file, $break_on_error);
$count_sql_stack_values = empty($id) ? count($this->sql_stack_values) : count($this->sql_stack_values[$id]);
$result = !empty($count_sql_stack_values);
for ( $i = 0; $i < $count_sql_stack_values; $i++ )
if ( empty($id) )
$sql = 'INSERT INTO ' . $table . '
(' . $this->sql_stack_fields . ') VALUES ' . $this->sql_stack_values[$i];
$sql = 'INSERT INTO ' . $table . '
(' . $this->sql_stack_fields[$id] . ') VALUES ' . $this->sql_stack_values[$id][$i];
$result &= $this->sql_query($sql, $transaction, $line, $file, $break_on_error);
return $result;
function sql_subquery($field, $sql, $line='', $file='', $break_on_error=true, $type=TYPE_INT)
// sub-queries doable
if ( !in_array(SQL_LAYER, array('mysql', 'mysql4')) || (($this->sql_version[0] + ($this->sql_version[1] / 100)) >= 4.01) )
return $sql;
// no sub-queries
$ids = array();
$result = $this->sql_query(trim($sql), false, $line, $file, $break_on_error);
while ( $row = $this->sql_fetchrow($result) )
$ids[] = $type == TYPE_INT ? intval($row[$field]) : '\'' . $this->sql_escape_string($row[$field]) . '\'';
return empty($ids) ? 'NULL' : implode(', ', $ids);
function sql_col_id($expr, $alias)
return in_array(SQL_LAYER, array('mysql', 'mysql4')) && (($this->sql_version[0] + ($this->sql_version[1] / 100)) <= 4.01) ? $alias : $expr;
function sql_get_version()
if ( empty($this->sql_version) )
+ − 530
+ − 531
+ − 533
+ − 534
+ − 535
+ − 536
$lo_version = explode('-', mysql_get_server_info());
$this->sql_version = explode('.', $lo_version[0]);
$this->sql_version = array(intval($this->sql_version[0]), intval($this->sql_version[1]), intval($this->sql_version[2]), $lo_version[1]);
case 'postgresql':
case 'mssql':
case 'mssql-odbc':
return $this->sql_version;
function sql_error()
if ( $this->_conn )
return mysql_error();
return array();
function sql_escape_string($t)
return mysql_real_escape_string($t);
function sql_close()
function sql_fetchrowset($query_id = 0)
if( !$query_id )
$query_id = $this->query_result;
if( $query_id )
while($this->rowset[$query_id] = mysql_fetch_array($query_id, MYSQL_ASSOC))
$result[] = $this->rowset[$query_id];
return $result;
return false;
