Bug #79132 [NEW]: PDO re-uses parameter values from earlier calls to execute()
| From: | love at sickpeople dot se | Date: | Thu, 16 Jan 2020 15:34:09 +0000 |
| Subject: | Bug #79132 [NEW]: PDO re-uses parameter values from earlier calls to execute() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-224939@lists.php.net to get a copy of this message | ||
From: love at sickpeople dot se
Operating system:
PHP version: 7.4.1
Package: PDO related
Bug Type: Bug
Bug description:PDO re-uses parameter values from earlier calls to execute()
Description:
------------
When executing the same statement, missing parameter values are filled
in with values from earlier executions instead of throwing an error.
This requires emulated PREPARE to be disabled.
Test script:
---------------
$host = '';
$db = '';
$user = '';
$pass = '';
$options = [
PDO::ATTR_EMULATE_PREPARES => false, /* required */
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
];
$pdo = new PDO("mysql:host=$host; dbname=$db; charset=utf8mb4", $user,
$pass, $options);
$stmt = $pdo->prepare('select ? a, ? b');
$set = [
['a', 'b'],
[1 => 'y'], /* first parameter is missing. Note the array key */
['x'], /* second parameter is missing */
];
foreach ($set as $params) {
try {
var_dump($stmt->execute($params),
$stmt->fetchAll(PDO::FETCH_ASSOC));
}
catch (Throwable $error) {
echo $error->getMessage() . "\n";
}
}
Expected result:
----------------
When emulated PREPARE is enabled, an error "SQLSTATE[HY093]: Invalid
parameter number: number of bound variables does not match number of
tokens" is thrown. The same error should be thrown instead of values
being re-used.
Actual result:
--------------
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "a"
["b"]=>
string(1) "b"
}
}
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "a"
["b"]=>
string(1) "y"
}
}
bool(true)
array(1) {
[0]=>
array(2) {
["a"]=>
string(1) "x"
["b"]=>
string(1) "y"
}
}
--
Edit bug report at https://bugs.php.net/bug.php?id=79132&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79132&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79132&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79132&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79132&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79132&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79132&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79132&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79132&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79132&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79132&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79132&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79132&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79132&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79132&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79132&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79132&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79132&r=mysqlcfg