#35368 [NEW]: PDO query does not work properly with serialize
| From: | lists at cyberlot dot net | Date: | Thu, 24 Nov 2005 15:07:37 +0000 |
| Subject: | #35368 [NEW]: PDO query does not work properly with serialize | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-88850@lists.php.net to get a copy of this message | ||
From: lists at cyberlot dot net
Operating system: Centos 4.1
PHP version: 6CVS-2005-11-24 (snap)
PHP Bug Type: PDO related
Bug description: PDO query does not work properly with serialize
Description:
------------
If you serialize a string, and run any of the escape functions,
mysql_escape, addslashes you can not use pdo->query to insert and it does
some sort of bind params translation on the string.
Bug exists in php5.1RC4 as I was using that version when I first found
this and upgraded to see if issue was resolved.
Using prepared statements ( and therefore not having to escape the data
before hand ) works.
Reproduce code:
---------------
<?
$dsn = 'mysql:dbname=alpha;host=localhost';
$login = 'alpha';
$password = 'alpha';
$db = new PDO($dsn, $login, $password);
$TEST['test']['test2'] = '1234';
$TEST['test']['test3'] = '555353';
$var = serialize($TEST);
echo "$var\n<BR>\n";
$var = mysql_escape_string($var);
$query = "INSERT INTO sessions SET value = '$var'";
$db->query($query);
$query = 'SELECT value FROM sessions';
$result = $db->query($query);
$row = $result->fetch();
echo $row[0]."\n<BR>\n";
?>
Expected result:
----------------
[root@alpha www_admin]# php index.php
a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}}
<BR>
a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}}
<BR>
Actual result:
--------------
[root@alpha www_admin]# php index.php
a:1:{s:4:"test";a:2:{s:5:"test2";s:4:"1234";s:5:"test3";s:6:"555353";}}
<BR>
a?:{s?:"test";a?:{s?:"test2";s?:"1234";s?:"test3";s?:"555353";}}
<BR>
--
Edit bug report at http://bugs.php.net/?id=35368&edit=1
--
Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=35368&r=trysnapshot4
Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=35368&r=trysnapshot50
Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=35368&r=trysnapshot51
Fixed in CVS: http://bugs.php.net/fix.php?id=35368&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=35368&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=35368&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=35368&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=35368&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=35368&r=support
Expected behavior: http://bugs.php.net/fix.php?id=35368&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=35368&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=35368&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=35368&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=35368&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=35368&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=35368&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=35368&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=35368&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=35368&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=35368&r=mysqlcfg