Bug #18375 Updated: addslashes/mysql_escape_string/mysql_real_... doesn't fit for multibyte string

From: Date: Sat, 20 Jul 2002 11:44:44 +0000
Subject: Bug #18375 Updated: addslashes/mysql_escape_string/mysql_real_... doesn't fit for multibyte string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14689@lists.php.net to get a copy of this message
ID: 18375 Updated by: Xuefer@21cn.com -Summary: addslashes doesn't fit for multibyte string Reported By: Xuefer@21cn.com -Status: Closed +Status: Open Bug Type: MySQL related Operating System: win2k PHP Version: 4.2.1 New Comment: i've tested with lastest build but sorry to tell u that, problem still there <?php $data = chr(160) . "'"; echo mysql_character_set_name(); $data = mysql_real_escape_string($data); mysql_query("SELECT '$data'"); // got error ?> win32 build and bundled libmysql still has no gbk support build-in gbk and other multibyte charset has to be built in (i don't bother why have to) get the same error MySQL - 1064 - You have an error in your SQL syntax near '' \''' at line 1 and i have to put gbk.conf in shared/charset dir in order to `fake' a charset which has to be built-in, although it's not right, but it's my only way mysql_character_set_name() return gbk if didn't put gbk.conf, return latin1, and apache/logs/error.log complain about missing charset file Previous Comments: ------------------------------------------------------------------------ [2002-07-20 03:49:07] georg@php.net To escape data please use mysql_real_escape_string function, which is implemented in the current cvs version. http://www.php.net/manual/en/function.mysql-real-escape-string.php. ------------------------------------------------------------------------ [2002-07-17 02:48:51] Xuefer@21cn.com tested with latest build still can't pass also checkout cvs source it's not libmysql 4 ------------------------------------------------------------------------ [2002-07-17 01:53:06] sniper@php.net Everyplace where php_addslashes is used, it's only used if the magic_quotes_* stuff is turned on (magic_quotes_runtime)..or is there someplace where it is used anyway? ------------------------------------------------------------------------ [2002-07-17 01:41:20] xuefer@21cn.com there're some other things to say. i always get my code runnign under magic_quote_* off but php_addslashes()(PHPAPI) is widely used internally there is a configuration flag "magic_quotes_sybase" for special to sybase, will there a flag for warping php_addslashes to mysql_escape_string ? ------------------------------------------------------------------------ [2002-07-17 01:39:36] sniper@php.net Can you please try this snapshot: http://snaps.php.net/win32/php4-win32-latest.zip The bundled mysql lib was updated recently..unfortunately I'm not able to test this as I don't have windowds machine to test it.. About magic_quotes_*: I personally would like to see them removed altogether... ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/18375 -- Edit this bug report at http://bugs.php.net/?id=18375&edit=1

« previous php.bugs (#14689) next »