note 71127 added to function.pdo-prepare
| From: | jacques at chester dot id dot au | Date: | Mon, 13 Nov 2006 14:07:18 +0000 |
| Subject: | note 71127 added to function.pdo-prepare | ||
| Groups: | php.notes php.notes | ||
| Request: | Send a blank email to php-notes+get-119661@lists.php.net to get a copy of this message | ||
Watch out: prepared statements on MySQL barf if you try to pass in substitution tables for sql
keywords, table names, view names and field names.
For example, this will not work:
$stmt = $dbh->prepare("SELECT :sqlAggregate( :fieldName) from :viewName";
You will get a MySQL error 1064 and a very unhelpful error message.
In short, you need to do string substitutions into your queries if you want configurable table
names, aggregate keywords etc etc.
Which doesn't help at all in the "protection from injection attacks" thing. A very
annoying discovery.
----
Server IP: 203.202.10.60
Probable Submitter: 124.243.142.107
----
Manual Page -- http://www.php.net/manual/en/function.pdo-prepare.php
Edit -- https://master.php.net/note/edit/71127
Del: integrated -- https://master.php.net/note/delete/71127/integrated
Del: useless -- https://master.php.net/note/delete/71127/useless
Del: bad code -- https://master.php.net/note/delete/71127/bad+code
Del: spam -- https://master.php.net/note/delete/71127/spam
Del: non-english -- https://master.php.net/note/delete/71127/non-english
Del: in docs -- https://master.php.net/note/delete/71127/in+docs
Del: other reasons-- https://master.php.net/note/delete/71127
Reject -- https://master.php.net/note/reject/71127
Search -- https://master.php.net/manage/user-notes.php