Bug #68031 [Fbk->Opn]: htmlspecialchars returns empty string, sometimes

From: Date: Wed, 17 Sep 2014 17:45:21 +0000
Subject: Bug #68031 [Fbk->Opn]: htmlspecialchars returns empty string, sometimes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187573@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68031&edit=1 ID: 68031 User updated by: pfenderd at bellsouth dot net Reported by: pfenderd at bellsouth dot net Summary: htmlspecialchars returns empty string, sometimes -Status: Feedback +Status: Open Type: Bug Package: Filter related Operating System: Linux PHP Version: 5.5.16 Block user comment: N Private report: N New Comment: <?php $xcs_welcome_msg = <<<XXX Thank you for taking the time to visit us here. We would like to invite you to come and visit our church during any of our services. We are known in the community as a friendly church where the Bible is faithfully taught and preached. Nothing quite compares to the joy of Christian friendship, and at God's First Church of Sample, we make it a priority to build lasting bonds between the members of our church family - bonds of genuine concern and commitment to one another. Best of all, this circle of care is ever widening. We would love to include you as well. We believe that studying the Bible is vital because it not only instructs us intellectually, but it also guides us spiritually. We believe and accept it as God's Word to man, a book that is alive and relevant to life today, and learning its truths can be a thrilling adventure. Opportunities for fellowship and learning are offered to every person at every age level by our staff of qualified teachers and leaders. We have Sunday school classes for children, youth, and adults in which principles from the Bible are taught in an open and personal forum. In addition to our Sunday school classes, we have a discipleship course that helps the new and even the most mature Christian to develop a lifelong, personal, and obedient relationship with Jesus Christ through Biblical teachings. Just as Jesus Christ came, "not to be ministered unto, but to minister..." we accept our responsibility to reach out in service to others. This applies both within the church family and outside our fellowship. Our primary reason for meeting together is to focus our attention on God, giving Him our worship, and receiving His blessing and inspiration. Each time we meet it is a special time of spiritual refreshment. XXX; $cs_welcome_msg = htmlspecialchars($xcs_welcome_msg); ?> <!doctype html> <html lang="en"> <head> <title>PHP Bug Test</title> </head> <body> <br> Original Variable value (<?php echo $xcs_welcome_msg;?>)<br><br> Value from htmlspecialchars() (<?php echo $cs_welcome_msg;?>)<br><br> </body> </html> Previous Comments: ------------------------------------------------------------------------ [2014-09-17 17:41:35] requinix@php.net Need actual source code, not just the output. I refreshed a few times and each time it worked correctly: string was intact and unchanged (except for a couple "s that were converted to &quot;s). ------------------------------------------------------------------------ [2014-09-17 15:33:59] pfenderd at bellsouth dot net The text that caused the problem was pure ASCII text and had no UTF-8 characters in it. Test case at http://dayspeak.net/test_php_bug_htmlspecialchars.php This simple test case failed to show the problem (worked properly). The fact that I could work around the problem by moving the problem-causing assignment down several lines of code indicates to me that the real problem is not in the htmlspecialchars() function itself but in the PHP script processor. ------------------------------------------------------------------------ [2014-09-17 05:18:09] rasmus@php.net Likely because you are getting invalid utf-8. Either specify the correct charset of your input to your htmlspecialchars() call, or filter out invalid utf-8 before the call. Outputting invalid UTF-8 is a security risk so previous your PHP 5.3-based application was vulnerable and now it isn't. ------------------------------------------------------------------------ [2014-09-16 20:17:02] requinix@php.net Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. ------------------------------------------------------------------------ [2014-09-16 19:24:23] pfenderd at bellsouth dot net Description: ------------ Occasionally,htmlspecialchars() returns an empty string value. It is consistent for certain string values and not a random problem. The string is usually long (several 100 chars). The problem did not exist in version 5.3.14 but does in later versions of 5.4 and 5.5.16. In a list of assignments to variables using htmlspecialchars(), it fails on the 5th of 10. The others always work properly, but the other string values are always much shorter than the one that fails. I created a simple test script, but the script always works. The problem is probably affected by the other code surrounding the problem statement. This is a serious problem because the code is used to maintain values in a database for a website and is not able to do so when database values cannot be seen in a management form. NOTE: I found a work-around solution to the problem by moving the line of code with the problem farther down the list of assignments. So it may not be a problem directly with htmlspecialchars(), but with the PHP script processor. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68031&edit=1

« previous php.bugs (#187573) next »