Bug #80340 [NEW]: PDO incorrectly parses string literals for platforms other than MySQL
| From: | morozov at tut dot by | Date: | Sun, 08 Nov 2020 19:31:42 +0000 |
| Subject: | Bug #80340 [NEW]: PDO incorrectly parses string literals for platforms other than MySQL | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-230205@lists.php.net to get a copy of this message | ||
From: morozov at tut dot by
Operating system: Linux
PHP version: 7.4.12
Package: PDO Core
Bug Type: Bug
Bug description:PDO incorrectly parses string literals for platforms other than MySQL
Description:
------------
When extracting prepared statement parameters, the SQL parser doesn't
take into account the dialect of the currently used database platform.
Specifically, it unconditionally expects string literals to use
backslash for escaping the closing delimiter (single or double quote),
although it's only supported by MySQL. It causes incorrect query parsing
on other platforms (e.g. PostgreSQL).
In the following script, the parser interprets the combination of the
backslash and the quote as part of the literal, so the following
question mark gets replaced with the $1 placeholder, however, it should
remain intact as part of the literal.
Test script:
---------------
$conn = new PDO('pgsql:...');
$sql = <<<'SQL'
SELECT '\'', ?'
SQL;
$stmt = $conn->prepare($sql);
$stmt->execute();
var_dump($stmt->fetchColumn());
Expected result:
----------------
postgres=# SELECT '\'', ?';
?column?
----------
\', ?
(1 row)
Actual result:
--------------
\', $1
--
Edit bug report at https://bugs.php.net/bug.php?id=80340&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80340&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80340&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80340&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80340&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80340&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80340&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80340&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80340&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80340&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80340&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80340&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80340&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80340&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80340&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80340&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80340&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80340&r=mysqlcfg