Bug #80355 [Dup->Opn]: Prepared statement broke with \ and -- characters
| From: | sartorua at gmail dot com | Date: | Thu, 12 Nov 2020 16:38:43 +0000 |
| Subject: | Bug #80355 [Dup->Opn]: Prepared statement broke with \ and -- characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230308@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80355&edit=1
ID: 80355
User updated by: sartorua at gmail dot com
Reported by: sartorua at gmail dot com
Summary: Prepared statement broke with \ and -- characters
-Status: Duplicate
+Status: Open
Type: Bug
-Package: PDO related
+Package: PDO PgSQL
Operating System: Ubuntu 20.04
PHP Version: 7.4.12
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
New minimal test code:
$pdo = new \PDO('pgsql:host=localhost;dbname=postgres', 'postgres',
'postgres');
$pdo->prepare("SELECT '\', '--' WHERE 'q' =
:e")->execute([':e' => 'q']);
Previous Comments:
------------------------------------------------------------------------
[2020-11-12 16:35:24] cmb@php.net
This is a duplicate of bug #79276.
------------------------------------------------------------------------
[2020-11-12 16:17:04] sartorua at gmail dot com
Description:
------------
SQL statement parser don't work with prepared parameters if SQL query string contains \ and --
characters (order matters).
PHP produces error:
Exception 'PDOException' with message 'SQLSTATE[HY093]: Invalid parameter number:
:e'
Test script:
---------------
$pdo = new \PDO('pgsql:host=localhost;dbname=postgres', 'postgres',
'postgres');
$s = $pdo->prepare("SELECT v FROM (VALUES ('\'),('--')) AS u (v) WHERE
u.v = :e");
$s->execute([':e' => 'foo']);
$s->fetchAll();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80355&edit=1