#35368 [NEW]: PDO query does not work properly with serialize

From: Date: Thu, 24 Nov 2005 15:07:37 +0000
Subject: #35368 [NEW]: PDO query does not work properly with serialize
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-88850@lists.php.net to get a copy of this message
From: lists at cyberlot dot net Operating system: Centos 4.1 PHP version: 6CVS-2005-11-24 (snap) PHP Bug Type: PDO related Bug description: PDO query does not work properly with serialize Description: ------------ If you serialize a string, and run any of the escape functions, mysql_escape, addslashes you can not use pdo->query to insert and it does some sort of bind params translation on the string. Bug exists in php5.1RC4 as I was using that version when I first found this and upgraded to see if issue was resolved. Using prepared statements ( and therefore not having to escape the data before hand ) works. Reproduce code: --------------- <? $dsn = 'mysql:dbname=alpha;host=localhost'; $login = 'alpha'; $password = 'alpha'; $db = new PDO($dsn, $login, $password); $TEST['test']['test2'] = '1234'; $TEST['test']['test3'] = '555353'; $var = serialize($TEST); echo "$var\n<BR>\n"; $var = mysql_escape_string($var); $query = "INSERT INTO sessions SET value = '$var'"; $db->query($query); $query = 'SELECT value FROM sessions'; $result = $db->query($query); $row = $result->fetch(); echo $row[0]."\n<BR>\n"; ?> Expected result: ---------------- [root@alpha www_admin]# php index.php a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}} <BR> a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}} <BR> Actual result: -------------- [root@alpha www_admin]# php index.php a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}} <BR> a?:{s?:"test";a?:{s?:"test2";s?:"1234";s?:"test3";s?:"555353";}} <BR> -- Edit bug report at http://bugs.php.net/?id=35368&edit=1 -- Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=35368&r=trysnapshot4 Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=35368&r=trysnapshot50 Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=35368&r=trysnapshot51 Fixed in CVS: http://bugs.php.net/fix.php?id=35368&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=35368&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=35368&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=35368&r=needscript Try newer version: http://bugs.php.net/fix.php?id=35368&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=35368&r=support Expected behavior: http://bugs.php.net/fix.php?id=35368&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=35368&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=35368&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=35368&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=35368&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=35368&r=dst IIS Stability: http://bugs.php.net/fix.php?id=35368&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=35368&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=35368&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=35368&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=35368&r=mysqlcfg

« previous php.bugs (#88850) next »