Bug #80355 [Opn->Dup]: Prepared statement broke with \ and -- characters

From: Date: Thu, 12 Nov 2020 16:47:19 +0000
Subject: Bug #80355 [Opn->Dup]: Prepared statement broke with \ and -- characters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230309@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80355&edit=1 ID: 80355 Updated by: cmb@php.net Reported by: sartorua at gmail dot com Summary: Prepared statement broke with \ and -- characters -Status: Open +Status: Duplicate Type: Bug Package: PDO PgSQL Operating System: Ubuntu 20.04 PHP Version: 7.4.12 Assigned To: cmb Block user comment: N Private report: N New Comment: Still a duplicate. Previous Comments: ------------------------------------------------------------------------ [2020-11-12 16:38:43] sartorua at gmail dot com New minimal test code: $pdo = new \PDO('pgsql:host=localhost;dbname=postgres', 'postgres', 'postgres'); $pdo->prepare("SELECT '\', '--' WHERE 'q' = :e")->execute([':e' => 'q']); ------------------------------------------------------------------------ [2020-11-12 16:35:24] cmb@php.net This is a duplicate of bug #79276. ------------------------------------------------------------------------ [2020-11-12 16:17:04] sartorua at gmail dot com Description: ------------ SQL statement parser don't work with prepared parameters if SQL query string contains \ and -- characters (order matters). PHP produces error: Exception 'PDOException' with message 'SQLSTATE[HY093]: Invalid parameter number: :e' Test script: --------------- $pdo = new \PDO('pgsql:host=localhost;dbname=postgres', 'postgres', 'postgres'); $s = $pdo->prepare("SELECT v FROM (VALUES ('\'),('--')) AS u (v) WHERE u.v = :e"); $s->execute([':e' => 'foo']); $s->fetchAll(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80355&edit=1

« previous php.bugs (#230309) next »