Bug #18375 Updated: addslashes/mysql_escape_string/mysql_real_... doesn't fit for multibyte string
| From: | Xuefer at 21cn dot com | Date: | Sat, 20 Jul 2002 11:44:44 +0000 |
| Subject: | Bug #18375 Updated: addslashes/mysql_escape_string/mysql_real_... doesn't fit for multibyte string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-14689@lists.php.net to get a copy of this message | ||
ID: 18375
Updated by: Xuefer@21cn.com
-Summary: addslashes doesn't fit for multibyte string
Reported By: Xuefer@21cn.com
-Status: Closed
+Status: Open
Bug Type: MySQL related
Operating System: win2k
PHP Version: 4.2.1
New Comment:
i've tested with lastest build
but sorry to tell u that, problem still there
<?php
$data = chr(160) . "'";
echo mysql_character_set_name();
$data = mysql_real_escape_string($data);
mysql_query("SELECT '$data'"); // got error
?>
win32 build and bundled libmysql still has no gbk support build-in
gbk and other multibyte charset has to be built in (i don't bother why
have to)
get the same error
MySQL - 1064 - You have an error in your SQL syntax near '' \''' at
line 1
and i have to put gbk.conf in shared/charset dir in order to `fake' a
charset which has to be built-in, although it's not right, but it's my
only way
mysql_character_set_name() return gbk
if didn't put gbk.conf, return latin1, and apache/logs/error.log
complain about missing charset file
Previous Comments:
------------------------------------------------------------------------
[2002-07-20 03:49:07] georg@php.net
To escape data please use mysql_real_escape_string
function, which is implemented in the current cvs version.
http://www.php.net/manual/en/function.mysql-real-escape-string.php.
------------------------------------------------------------------------
[2002-07-17 02:48:51] Xuefer@21cn.com
tested with latest build
still can't pass
also checkout cvs source
it's not libmysql 4
------------------------------------------------------------------------
[2002-07-17 01:53:06] sniper@php.net
Everyplace where php_addslashes is used, it's only used
if the magic_quotes_* stuff is turned on (magic_quotes_runtime)..or is
there someplace where it is
used anyway?
------------------------------------------------------------------------
[2002-07-17 01:41:20] xuefer@21cn.com
there're some other things to say.
i always get my code runnign under magic_quote_* off
but php_addslashes()(PHPAPI) is widely used internally
there is a configuration flag "magic_quotes_sybase" for special to
sybase, will there a flag for warping php_addslashes to
mysql_escape_string ?
------------------------------------------------------------------------
[2002-07-17 01:39:36] sniper@php.net
Can you please try this snapshot:
http://snaps.php.net/win32/php4-win32-latest.zip
The bundled mysql lib was updated recently..unfortunately
I'm not able to test this as I don't have windowds machine
to test it..
About magic_quotes_*: I personally would like to see them removed
altogether...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18375
--
Edit this bug report at http://bugs.php.net/?id=18375&edit=1