Bug #44639 [Com]: PDO quotes integers in prepared statement

From: Date: Sun, 26 Jan 2014 18:12:50 +0000
Subject: Bug #44639 [Com]: PDO quotes integers in prepared statement
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184015@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=44639&edit=1

 ID:                 44639
 Comment by:         mightyuhu@php.net
 Reported by:        jgauld at blueyonder dot co dot uk
 Summary:            PDO quotes integers in prepared statement
 Status:             Open
 Type:               Bug
 Package:            PDO Core
 Operating System:   *
 PHP Version:        5.*
 Block user comment: N
 Private report:     N

 New Comment:

Confirmed on php 5.3.10-1ubuntu3.8 and MySQL 5.5.32


Previous Comments:
------------------------------------------------------------------------
[2012-12-05 04:02:03] alek0585 at mail dot ru

Yeah! Try this $db->setAttribute(PDO::ATTR_EMULATE_PREPARES, false); and you can 
use that!
foreach($data as $key => $value) {
            $stmt->bindParam( ":".$key, $value, (is_int($value) ? PDO::PARAM_INT : 
PDO::PARAM_STR));
        }
but you should be careful with types of vars

------------------------------------------------------------------------
[2012-03-12 10:15:44] alvaro at demogracia dot com

This only happens on emulated parameter binding, i.e. when PDO::ATTR_EMULATE_PREPARES is TRUE.

------------------------------------------------------------------------
[2012-02-25 06:28:34] preludeinz at gmail dot com

Please fix! I can't do my course's lab exercise (without introducing a SQL 
injection vulnerability) without this feature.

------------------------------------------------------------------------
[2012-01-13 19:50:40] engin at e-php dot net

It's really sad seeing this aged bug is not gonna fixed.

------------------------------------------------------------------------
[2011-12-13 22:33:36] stephen-d at rogers dot com

I am surprised that something this simple has been unfixed for so long.

I wasted 8 hours trying to figure out "my" mistake. Thinking that it was a PDO bug was
inconceivable.

I finally turned on MySQL logging and saw that the numeric argument was being enclosed in quotes. I
posted to a web site for help and a kind person sent me this link.

For others struggling with this, the work-around is to type caste all numeric values that will
passed to PBO.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=44639


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=44639&edit=1


Thread (25 messages)

« previous php.bugs (#184015) next »