Req #79276 [NEW]: PDO_API int pdo_parse_params() ignores any placeholder between two '\'
| From: | v-yitam at microsoft dot com | Date: | Sat, 15 Feb 2020 00:19:22 +0000 |
| Subject: | Req #79276 [NEW]: PDO_API int pdo_parse_params() ignores any placeholder between two '\' | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-225583@lists.php.net to get a copy of this message | ||
From: v-yitam at microsoft dot com
Operating system: Irrelevant
PHP version: Irrelevant
Package: PDO Core
Bug Type: Feature/Change Request
Bug description:PDO_API int pdo_parse_params() ignores any placeholder between two '\'
Description:
------------
PDO_API int pdo_parse_params() in ext/pdo/pdo_sql_parser.re ignores
(skips) any placeholder in between two backslashes
\
If I replaced the backslash \ with forward slash '/' in the query, the
query succeeded and returned the row as expected.
If the following line is removed the 'problem' is gone:
https://github.com/php/php-src/blob/master/ext/pdo/pdo_sql_parser.re#L59
If this is intentional (by design), please explain or let us know if
there is a workaround.
Test script:
---------------
$dbh = new PDO("sqlsrv:server=$server;Database = $db", $uid, $pwd);
$tableName = 'testPDO';
$create_sql = "CREATE TABLE $tableName(id int NOT NULL, langcode
varchar(12), revision_id int, [path] nvarchar(255), [alias]
nvarchar(255))"
$dbh->exec($create_sql1);
$insert_sql = "INSERT INTO $tableName(id, langcode, revision_id, [path],
[alias]) VALUES (4, 'en', 4, '/node/3', '/')";
$dbh->exec($insert_sql);
$sql = "SELECT * FROM $tableName WHERE [path] LIKE :path ESCAPE '\' AND
[langcode] like :lang ESCAPE '\'";
$args = [
':path' => '%node%',
':lang' => 'en'
];
$sth = $dbh->prepare($sql);
$sth->execute($args);
$row = $sth->fetch(PDO::FETCH_NUM);
var_dump($row);
Expected result:
----------------
array(5) {
[0]=>
string(1) "4"
[1]=>
string(2) "en"
[2]=>
string(1) "4"
[3]=>
string(7) "/node/3"
[4]=>
string(1) "/"
}
Actual result:
--------------
PHP Fatal error: Uncaught PDOException: SQLSTATE[HY093]: Invalid
parameter number: parameter was not defined in
C:\Workspace\Test\pdo_1093.php:53
--
Edit bug report at https://bugs.php.net/bug.php?id=79276&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79276&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79276&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79276&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79276&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79276&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79276&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79276&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79276&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79276&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79276&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79276&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79276&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79276&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79276&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79276&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79276&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79276&r=mysqlcfg