Bug #64638 [Asn->Csd]: Fetching resultsets from stored procedure with cursor fails

From: Date: Fri, 18 Dec 2020 09:26:49 +0000
Subject: Bug #64638 [Asn->Csd]: Fetching resultsets from stored procedure with cursor fails
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231142@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64638&edit=1 ID: 64638 Updated by: nikic@php.net Reported by: DimonSoft at sa-sec dot org Summary: Fetching resultsets from stored procedure with cursor fails -Status: Assigned +Status: Closed Type: Bug Package: MySQLi related Operating System: Irrelevant PHP Version: 5.3, 5.4, 5.5, 5.6, 7 -Assigned To: mysql +Assigned To: nikic Block user comment: N Private report: N New Comment: This should be fixed by https://github.com/php/php-src/commit/bc166844e37a6e1531a18dc0916fbe508152fc6c. Previous Comments: ------------------------------------------------------------------------ [2019-03-25 02:48:20] maxosky at gmail dot com Same problem in PHP 7.1.26, always not fixed. ------------------------------------------------------------------------ [2015-07-28 13:05:03] andrey@php.net delimiter // CREATE PROCEDURE test() BEGIN declare test_var varchar(100) default "ciao"; declare bNoMoreRows bool default false; declare test_cursor cursor for select id from tmp_folder; declare continue handler for not found set bNoMoreRows := true; create temporary table tmp_folder select "test" as id; open test_cursor; fetch test_cursor into test_var; close test_cursor; select test_var; drop temporary table if exists tmp_folder; END// ./php -r '$c=mysqli_connect("127.0.0.1", "root","", "test");$s=$c->prepare("CALL test()");var_dump($s->execute());var_dump($s->get_result());' ------------------------------------------------------------------------ [2015-07-28 13:04:09] andrey@php.net Crash reproduced with mysqli ------------------------------------------------------------------------ [2015-07-28 13:03:30] andrey@php.net Crash reproduced with 5.4, 5.5, 5.6 and 7 . Probably has something to do with the cursor opened in the SP. A SP which also generates a result set, like BEGIN SELECT 1; END doesn't crash. ------------------------------------------------------------------------ [2013-09-23 06:41:50] flannell at gmail dot com Found the problem in my scenario. You can't use cursors in stored procedures using PDO and having this in your connection params: $this->setAttribute(PDO::ATTR_EMULATE_PREPARES, false); If removed, or set to true (the default), it starts to work. This does raise a possible SQL injection issue as the SQL statement and params are no longer sent to the server independently. Hope this helps someone. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=64638 -- Edit this bug report at https://bugs.php.net/bug.php?id=64638&edit=1

« previous php.bugs (#231142) next »