Parameters in parameter_array
will be
substituted for placeholders in the prepared statement in order.
Elements of this array will be converted to strings by calling this
function.
Any parameters in parameter_array
which
start and end with single quotes will be taken as the name of a
file to read and send to the database server as the data for the
appropriate placeholder.
If you wish to store a string which actually begins and ends with
single quotes, you must add a space or other non-single-quote character
to the beginning or end of the parameter, which will prevent the
parameter from being taken as a file name. If this is not an option,
then you must use another mechanism to store the string, such as
executing the query directly with odbc_exec()).
If you need to call a stored procedure using INOUT or OUT parameters,
the recommended workaround is to use a native extension for your database
(for example, mssql for MS SQL Server,
or oci8 for Oracle).
ChangeLog
Version
Description
4.2.0
File reading is now subject to safe mode and
open-basedir restrictions
in parameters_array
.
4.1.1
Remote files
are no longer supported in parameters_array
.