Bug #61327 [Opn->Fbk]: PDO complain about Invalid parameter number

From: Date: Mon, 08 Aug 2016 17:43:14 +0000
Subject: Bug #61327 [Opn->Fbk]: PDO complain about Invalid parameter number
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203094@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61327&edit=1 ID: 61327 Updated by: cmb@php.net Reported by: daniel dot caillibaud at sesamath dot net Summary: PDO complain about Invalid parameter number -Status: Open +Status: Feedback Type: Bug Package: PDO Core Operating System: linux PHP Version: 5.3.10 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This doesn't appear to be a general PDO problem; at least I can't reproduce it with pdo_sqlite, see <https://3v4l.org/64MQv>. So if this problem persists with current PHP versions, we need more specific information to be able to address the issue. Previous Comments: ------------------------------------------------------------------------ [2012-03-08 15:27:25] daniel dot caillibaud at sesamath dot net Description: ------------ The query INSERT INTO $table VALUES (\"first value\"); -- dam'd quote INSERT INTO $table VALUES (\"foo : ba'r \"), (\"foo.:bar\"); Throws Warning: PDOStatement::execute(): SQLSTATE[HY093]: Invalid parameter number: no parameters were bound But doesn't - without first query before comment - without comment - with escaped quote - with space after last colon Test script: --------------- // This query doesn't work $q1 = "INSERT INTO $table VALUES (\"first value\"); -- dam'd quote INSERT INTO $table VALUES (\"foo : ba'r \"), (\"foo.:bar\"); "; // But all these doesn't have any pb $q2 = "-- dam'd quote INSERT INTO $table VALUES (\"foo : ba'r \"), (\"foo.:bar\"); "; // without first one (before comment) $q3 = "INSERT INTO $table VALUES (\"first value\"); INSERT INTO $table VALUES (\"foo : ba'r \"), (\"foo.:bar\"); "; // without comment $q4 = "INSERT INTO $table VALUES (\"first value\"); -- dam'd quote INSERT INTO $table VALUES (\"foo : ba\'r \"), (\"foo.:bar\"); "; // with escaped quote $q5 = "INSERT INTO $table VALUES (\"first value\"); -- dam'd quote INSERT INTO $table VALUES (\"foo : ba'r \"), (\"foo.: bar\"); "; // with space after last colon try { $pdo = new PDO($dsn, $user, $pass, $options); $stmt = $pdo->prepare($query); $stmt->execute(); } catch (Exception $e) { echo "Failed : " .$e->getMessage(); } Expected result: ---------------- No warning Actual result: -------------- Warning: PDOStatement::execute(): SQLSTATE[HY093]: Invalid parameter number: no parameters were bound ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=61327&edit=1

« previous php.bugs (#203094) next »