Bug #61327 [Opn->Fbk]: PDO complain about Invalid parameter number
| From: | cmb@php.net | Date: | Mon, 08 Aug 2016 17:43:14 +0000 |
| Subject: | Bug #61327 [Opn->Fbk]: PDO complain about Invalid parameter number | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203094@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61327&edit=1
ID: 61327
Updated by: cmb@php.net
Reported by: daniel dot caillibaud at sesamath dot net
Summary: PDO complain about Invalid parameter number
-Status: Open
+Status: Feedback
Type: Bug
Package: PDO Core
Operating System: linux
PHP Version: 5.3.10
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This doesn't appear to be a general PDO problem; at least I can't
reproduce it with pdo_sqlite, see <https://3v4l.org/64MQv>.
So if this problem persists with current PHP versions, we need
more specific information to be able to address the issue.
Previous Comments:
------------------------------------------------------------------------
[2012-03-08 15:27:25] daniel dot caillibaud at sesamath dot net
Description:
------------
The query
INSERT INTO $table VALUES (\"first value\");
-- dam'd quote
INSERT INTO $table VALUES (\"foo : ba'r \"),
(\"foo.:bar\");
Throws
Warning: PDOStatement::execute(): SQLSTATE[HY093]: Invalid parameter number: no parameters were
bound
But doesn't
- without first query before comment
- without comment
- with escaped quote
- with space after last colon
Test script:
---------------
// This query doesn't work
$q1 = "INSERT INTO $table VALUES (\"first value\");
-- dam'd quote
INSERT INTO $table VALUES (\"foo : ba'r \"),
(\"foo.:bar\"); ";
// But all these doesn't have any pb
$q2 = "-- dam'd quote
INSERT INTO $table VALUES (\"foo : ba'r \"),
(\"foo.:bar\"); "; // without first one (before comment)
$q3 = "INSERT INTO $table VALUES (\"first value\");
INSERT INTO $table VALUES (\"foo : ba'r \"),
(\"foo.:bar\"); "; // without comment
$q4 = "INSERT INTO $table VALUES (\"first value\");
-- dam'd quote
INSERT INTO $table VALUES (\"foo : ba\'r \"),
(\"foo.:bar\"); "; // with escaped quote
$q5 = "INSERT INTO $table VALUES (\"first value\");
-- dam'd quote
INSERT INTO $table VALUES (\"foo : ba'r \"),
(\"foo.: bar\"); "; // with space after last colon
try {
$pdo = new PDO($dsn, $user, $pass, $options);
$stmt = $pdo->prepare($query);
$stmt->execute();
}
catch (Exception $e) {
echo "Failed : " .$e->getMessage();
}
Expected result:
----------------
No warning
Actual result:
--------------
Warning: PDOStatement::execute(): SQLSTATE[HY093]: Invalid parameter number: no parameters were
bound
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=61327&edit=1