Bug #64638 [Asn->Csd]: Fetching resultsets from stored procedure with cursor fails
| From: | nikic@php.net | Date: | Fri, 18 Dec 2020 09:26:49 +0000 |
| Subject: | Bug #64638 [Asn->Csd]: Fetching resultsets from stored procedure with cursor fails | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231142@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64638&edit=1
ID: 64638
Updated by: nikic@php.net
Reported by: DimonSoft at sa-sec dot org
Summary: Fetching resultsets from stored procedure with
cursor fails
-Status: Assigned
+Status: Closed
Type: Bug
Package: MySQLi related
Operating System: Irrelevant
PHP Version: 5.3, 5.4, 5.5, 5.6, 7
-Assigned To: mysql
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This should be fixed by https://github.com/php/php-src/commit/bc166844e37a6e1531a18dc0916fbe508152fc6c.
Previous Comments:
------------------------------------------------------------------------
[2019-03-25 02:48:20] maxosky at gmail dot com
Same problem in PHP 7.1.26, always not fixed.
------------------------------------------------------------------------
[2015-07-28 13:05:03] andrey@php.net
delimiter //
CREATE PROCEDURE
test()
BEGIN
declare test_var varchar(100) default "ciao";
declare bNoMoreRows bool default false;
declare test_cursor cursor for
select id from tmp_folder;
declare continue handler for not found set bNoMoreRows := true;
create temporary table tmp_folder select "test" as id;
open test_cursor;
fetch test_cursor into test_var;
close test_cursor;
select test_var;
drop temporary table if exists tmp_folder;
END//
./php -r '$c=mysqli_connect("127.0.0.1", "root","",
"test");$s=$c->prepare("CALL
test()");var_dump($s->execute());var_dump($s->get_result());'
------------------------------------------------------------------------
[2015-07-28 13:04:09] andrey@php.net
Crash reproduced with mysqli
------------------------------------------------------------------------
[2015-07-28 13:03:30] andrey@php.net
Crash reproduced with 5.4, 5.5, 5.6 and 7 . Probably has something to do with the cursor opened in
the SP. A SP which also generates a result set, like BEGIN SELECT 1; END doesn't crash.
------------------------------------------------------------------------
[2013-09-23 06:41:50] flannell at gmail dot com
Found the problem in my scenario. You can't use cursors in stored procedures
using PDO and having this in your connection params:
$this->setAttribute(PDO::ATTR_EMULATE_PREPARES, false);
If removed, or set to true (the default), it starts to work.
This does raise a possible SQL injection issue as the SQL statement and params
are no longer sent to the server independently.
Hope this helps someone.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64638
--
Edit this bug report at https://bugs.php.net/bug.php?id=64638&edit=1