#23344 [Opn->Dup]: wrong variable in DB common
| From: | philip@php.net | Date: | Sat, 26 Apr 2003 22:59:36 +0000 |
| Subject: | #23344 [Opn->Dup]: wrong variable in DB common | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-15585@lists.php.net to get a copy of this message | ||
ID: 23344
Updated by: philip@php.net
Reported By: tomas at dupoint dot com
-Status: Open
+Status: Duplicate
Bug Type: PEAR related
Operating System: win2000
PHP Version: 4.3.0
New Comment:
This was fixed on Mon Jul 29 07:21:30 2002, although, thanks for the
report :)
http://cvs.php.net/diff.php/pear/DB/DB/common.php?r1=1.9&r2=1.10
Previous Comments:
------------------------------------------------------------------------
[2003-04-25 08:33:31] tomas at dupoint dot com
OK...
A WHERE-statement is sent to this method. Look how it's set in $where
but when it's used the variable $sql is used instead!! The query
becomes "UPDATE $table SET $set WHERE UPDATE $table SET $set"
The error is marked with >>>>
function buildManipSQL($table, $table_fields, $mode, $where =
false)
{
if (count($table_fields)==0) {
$this->raiseError(DB_ERROR_NEED_MORE_DATA);
}
$first = true;
switch($mode) {
case DB_AUTOQUERY_INSERT:
$values = '';
$names = '';
while (list(, $value) = each($table_fields)) {
if ($first) {
$first = false;
} else {
$names .= ',';
$values .= ',';
}
$names .= $value;
$values .= '?';
}
return "INSERT INTO $table ($names) VALUES ($values)";
break;
case DB_AUTOQUERY_UPDATE:
$set = '';
while (list(, $value) = each($table_fields)) {
if ($first) {
$first = false;
} else {
$set .= ',';
}
$set .= "$value = ?";
}
$sql = "UPDATE $table SET $set";
if ($where) {
>>>> $sql .= " WHERE $sql";
}
return $sql;
break;
default:
$this->raiseError(DB_ERROR_SYNTAX);
}
}
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23344&edit=1