Bug #77490 [NEW]: PDO does not throw an exception when more values than parameters are used
| From: | love at sickpeople dot se | Date: | Sun, 20 Jan 2019 00:12:45 +0000 |
| Subject: | Bug #77490 [NEW]: PDO does not throw an exception when more values than parameters are used | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-219091@lists.php.net to get a copy of this message | ||
From: love at sickpeople dot se
Operating system:
PHP version: 7.3.1
Package: PDO related
Bug Type: Bug
Bug description:PDO does not throw an exception when more values than parameters are used
Description:
------------
When using ERRMODE_EXCEPTION, a call to execute() with *more values*
than parameters does not throw an exception. The call fails with false.
The query is not executed by the db.
The docs of execute() states: "Binding more values than specified is not
possible; if more keys exist in input_parameters than in the SQL
specified in the PDO::prepare(), then the statement will fail and an
error is emitted."
I've tested this with Mysqlnd.
Test script:
---------------
$host = '';
$db = '';
$user = '';
$pass = '';
$options = [
PDO::ATTR_EMULATE_PREPARES => false, /* required */
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
];
$pdo = new PDO("mysql:host=$host; dbname=$db; charset=utf8mb4", $user,
$pass, $options);
$stmt = $pdo->prepare('select ? a, ? b');
try {
var_dump($stmt->execute([0]), $stmt->fetchAll(PDO::FETCH_ASSOC));
}
catch (Throwable $error) {
echo $error->getMessage() . "\n";
}
var_dump($stmt->execute([0, 1]), $stmt->fetchAll(PDO::FETCH_ASSOC));
try {
var_dump($stmt->execute([0, 1, 2]),
$stmt->fetchAll(PDO::FETCH_ASSOC));
}
catch (Throwable $error) {
echo $error->getMessage() . "\n";
}
Expected result:
----------------
I expect both execute() with the wrong number of values to throw an
exception.
Actual result:
--------------
The last execute() fails with false and does not throw an exception.
Output from the test script:
SQLSTATE[HY093]: Invalid parameter number
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "0"
["b"]=>
string(1) "1"
}
}
bool(false)
array(0) {
}
--
Edit bug report at https://bugs.php.net/bug.php?id=77490&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77490&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77490&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77490&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77490&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77490&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77490&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77490&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77490&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77490&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77490&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77490&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77490&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77490&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77490&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77490&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77490&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77490&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77490&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77490&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77490&r=mysqlcfg