#35368 [Com]: PDO query does not work properly with serialize
| From: | uggabc at yahoo dot cn | Date: | Thu, 24 Dec 2009 01:02:11 +0000 |
| Subject: | #35368 [Com]: PDO query does not work properly with serialize | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-146080@lists.php.net to get a copy of this message | ||
ID: 35368
Comment by: uggabc at yahoo dot cn
Reported By: lists at cyberlot dot net
Status: Suspended
Bug Type: PDO related
Operating System: *
PHP Version: 6CVS, 5CVS
Assigned To: wez
New Comment:
It is a wonderful article,I like it!Welcome to read following news:
<a href="http://www.uggbootsstore.net/">uggs
outlet</a>
Previous Comments:
------------------------------------------------------------------------
[2009-10-31 01:24:28] ET at 126 dot COM
<a href="http://www.baidu.com">baidu</a>
[url=www.google.com]google[/url]
[url=http://www.sina.com]sina[/url]
[url="http://www.baidu.com"]baidu[/url]
[link=http://www.yahoo.com]yahoo[/link]
------------------------------------------------------------------------
[2009-10-24 00:53:35] linlixiang123 at 126 dot com
As there are number of ways by which <a
href="http://www.jordanshoes100.com">jordan
shoes</a> your hair, but
you will find using hair straightener easy. <a
href="http://www.jordanshoes100.com">air jordan
shoes</a> Today
something that no person will be without is his or her <a
href="http://www.jordanshoes100.com">cheap jordan
shoes</a> .Since hair
straightener has become an essential part of so it is wise to check that
they are in good condition and do not need replacing if you have had
your.
------------------------------------------------------------------------
[2005-11-27 22:11:06] wez@php.net
We managed to reproduce the problem; it's a problem with the query
rewriter when it maps :name to ?. If the string is embedded in the SQL
using single quotes, but has double quotes backslashed, the string it
too tricky for the parser to follow, and it ends up transforming parts
of the serialized string that it shouldn't.
There are three possible workarounds for this issue, in order of
preference:
- Don't embed serialized data into the query string; use bound
parameters (that's what they're there for). In future versions of PDO,
prepared statements may be cacheable in persistent connections, leading
to a performance gain.
- Use PDO::quote() to correctly quote the string
- Use PDO::exec() to fire off this UPDATE/INSERT statement; it uses an
alternate API that doesn't need to handle parameters.
------------------------------------------------------------------------
[2005-11-25 16:40:35] tony2001@php.net
This is fixed in CVS, get a fresh snapshot and try again.
------------------------------------------------------------------------
[2005-11-25 16:32:07] lists at cyberlot dot net
To try and narrow this down and be able to play with the code more I
recompiled PHP 5.1 without pdo support then compiled seperate modules
however I could not get pdo_mysql to compile.
I phpized ./configure and make and get the following error
checking for MySQL support for PDO... yes, shared
checking for mysql_config... /usr/bin/mysql_config
checking for mysql_query... no
configure: error: mysql_query missing!?
Might be related? So I forced a install of pdo_mysql RC2
The bug goes away, Same exact script but everything is working...
So its either a diffrence between pdo_mysql RC2 or some wierd issue
with shared vs compiled in.
I hope that helps somehow?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/35368
--
Edit this bug report at http://bugs.php.net/?id=35368&edit=1