Bug #74220 [NEW]: Special crafted SQL statement trips PDO

From: Date: Tue, 07 Mar 2017 22:34:18 +0000
Subject: Bug #74220 [NEW]: Special crafted SQL statement trips PDO
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207730@lists.php.net to get a copy of this message
From: mfischer Operating system: Ubuntu 14.04 PHP version: 7.1.2 Package: PDO PgSQL Bug Type: Bug Bug description:Special crafted SQL statement trips PDO Description: ------------ I initially reported this at https://github.com/cakephp/cakephp/issues/10373 but was told "If you can reproduce this issue with raw PDO, then its not a CakePHP issue." The provided SQL statement, as executed with PDO, does not insert the provided data correctly. Prerequisites: create a db role / database table: postgres=# create role username login password 'password'; CREATE ROLE postgres=# create database db owner username; CREATE DATABASE postgres=# \c db You are now connected to database "db" as user "postgres". db=# set role username; SET db=> create table models(field varchar(12)); CREATE TABLE The provided SQL statement (see test script) is valid Postgres syntax. Test script: --------------- <?php $pdo = new PDO('pgsql:host=localhost;dbname=db', 'username', 'password'); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $sql = <<<SQL INSERT INTO models (field) values('\'':1'); SQL; $pdo->query($sql); $result = $pdo->query('SELECT * FROM models'); var_dump($result->fetchAll()); Expected result: ---------------- array(1) { [0]=> array(2) { ["field"]=> string(4) "\':1" [0]=> string(4) "\':1" } } Actual result: -------------- array(1) { [0]=> array(2) { ["field"]=> string(4) "\'$1" [0]=> string(4) "\'$1" } } -- Edit bug report at https://bugs.php.net/bug.php?id=74220&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74220&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74220&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74220&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74220&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74220&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74220&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74220&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74220&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74220&r=support Expected behavior: https://bugs.php.net/fix.php?id=74220&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74220&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74220&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74220&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74220&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74220&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74220&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74220&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74220&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74220&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74220&r=mysqlcfg

« previous php.bugs (#207730) next »