Bug #80355 [Opn->Dup]: Prepared statement broke with \ and -- characters
| From: | cmb@php.net | Date: | Thu, 12 Nov 2020 16:35:24 +0000 |
| Subject: | Bug #80355 [Opn->Dup]: Prepared statement broke with \ and -- characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230307@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80355&edit=1
ID: 80355
Updated by: cmb@php.net
Reported by: sartorua at gmail dot com
Summary: Prepared statement broke with \ and -- characters
-Status: Open
+Status: Duplicate
Type: Bug
Package: PDO related
Operating System: Ubuntu 20.04
PHP Version: 7.4.12
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This is a duplicate of bug #79276.
Previous Comments:
------------------------------------------------------------------------
[2020-11-12 16:17:04] sartorua at gmail dot com
Description:
------------
SQL statement parser don't work with prepared parameters if SQL query string contains \ and --
characters (order matters).
PHP produces error:
Exception 'PDOException' with message 'SQLSTATE[HY093]: Invalid parameter number:
:e'
Test script:
---------------
$pdo = new \PDO('pgsql:host=localhost;dbname=postgres', 'postgres',
'postgres');
$s = $pdo->prepare("SELECT v FROM (VALUES ('\'),('--')) AS u (v) WHERE
u.v = :e");
$s->execute([':e' => 'foo']);
$s->fetchAll();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80355&edit=1