Bug #72065 [NEW]: Single backslash problem in parametrized query
| From: | jaro at ttx dot sk | Date: | Wed, 20 Apr 2016 15:11:41 +0000 |
| Subject: | Bug #72065 [NEW]: Single backslash problem in parametrized query | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-200663@lists.php.net to get a copy of this message | ||
From: jaro at ttx dot sk
Operating system: *
PHP version: Irrelevant
Package: PDO related
Bug Type: Bug
Bug description:Single backslash problem in parametrized query
Description:
------------
There is a problem with single backlash string in parametrized qurery.
When I try run test script it gives me error. String with backslash is
quoted with PDO::quote with posgresql driver. It seems valid if not used
with parametrized query with next string with quotes.
Valid sql:
INSERT INTO test_quote
("id","text","text2","text3","text4") VALUES
(1,'aaa',?,'\','test4')
Invalid sql:
INSERT INTO test_quote
("id","text","text2","text3","text4") VALUES
(1,'aaa','\',?,'test4')
It affects all versions of php from 5.5 and above what I tested.
Test script:
---------------
$dbh = new PDO('pgsql:host=postgres;dbname=test','test_user','test');
$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$dbh->exec('DROP TABLE IF EXISTS test_quote');
$dbh->exec('CREATE TABLE test_quote ( id int, text varchar(40), text2
varchar(40), text3 varchar(40), text4 varchar(40) )');
$sql = <<<'EOT'
INSERT INTO test_quote
("id","text","text2","text3","text4") VALUES
(1,?,'\',?,'test4')
EOT;
try {
$statement = $dbh->prepare($sql);
$statement->bindValue( 1 , 'test1', PDO::PARAM_STR);
$statement->bindValue( 2 , 'test3', PDO::PARAM_STR);
$statement->setFetchMode(PDO::FETCH_ASSOC);
$statement->execute();
} catch (PDOException $e) {
echo 'Connection failed: ' . $e->getMessage();
}
Actual result:
--------------
Connection failed: SQLSTATE[42601]: Syntax error: 7 ERROR: syntax error
at or near ","
LINE 1: ...,"text","text2","text3","text4") VALUES
(1,$1,'\',?,'test4')
^
--
Edit bug report at https://bugs.php.net/bug.php?id=72065&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72065&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72065&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72065&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72065&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72065&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72065&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72065&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72065&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72065&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72065&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72065&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72065&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72065&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72065&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72065&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72065&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72065&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72065&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72065&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72065&r=mysqlcfg