sqlmapproject/sqlmap · error · ProgrammingError

parameter binding is not supported; pass a fully-formed quer

Error message

parameter binding is not supported; pass a fully-formed query string

What it means

Error "parameter binding is not supported; pass a fully-formed query string" thrown in sqlmapproject/sqlmap.

Source

Thrown at extra/dbwire/clickhouse.py:70

    # keep text as str; hand back raw bytes only when a value is not valid UTF-8 (sqlmap then hex-encodes it)
    if value is None:
        return None
    try:
        return value.decode("utf-8")
    except UnicodeDecodeError:
        return value

class Cursor(object):
    def __init__(self, connection):
        self.connection = connection
        self.description = None
        self.rowcount = -1
        self._rows = []
        self._pos = 0

    def execute(self, query, params=None):
        if params is not None:
            raise ProgrammingError("parameter binding is not supported; pass a fully-formed query string")
        self.description, self.rowcount, self._rows, self._pos = None, -1, [], 0
        self.description, self._rows = self.connection._query(query)
        self.rowcount = len(self._rows)
        return self

    def fetchall(self):
        retVal = self._rows[self._pos:]
        self._pos = len(self._rows)
        return retVal

    def fetchone(self):
        if self._pos >= len(self._rows):
            return None
        retVal = self._rows[self._pos]
        self._pos += 1
        return retVal

    def close(self):

View on GitHub (pinned to 0a35b20e39)

When it happens

Trigger: Thrown at extra/dbwire/clickhouse.py:70 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of sqlmapproject/sqlmap@0a35b20e39 (2026-08-26). Data as JSON: /api/errors/0c8cc67c32aa6ca7. Report an issue: GitHub.