Bug #68320 [Opn->Nab]: str_replace not binary safe
| From: | requinix@php.net | Date: | Wed, 29 Oct 2014 00:12:29 +0000 |
| Subject: | Bug #68320 [Opn->Nab]: str_replace not binary safe | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188350@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68320&edit=1
ID: 68320
Updated by: requinix@php.net
Reported by: zf at ancientrock dot org
Summary: str_replace not binary safe
-Status: Open
+Status: Not a bug
Type: Bug
Package: Scripting Engine problem
Operating System: CentOS 6.5 x64
PHP Version: 5.6.2
Block user comment: N
Private report: N
New Comment:
str_replace() is binary-safe. The problem is that the encoding you're using is not safe for
writing PHP code in*, and in fact you'll get similar problems with other programming languages.
GBK with a database can even expose you to SQL injection.
You need to use something other than GBK for your code. Like UTF-8 or -16.
* Briefly, GBK will encode some characters into \xHH\x5C (ie, a byte followed by a \x5C byte). \x5C
is a backslash and that can cause problems because it's used for escape sequences in strings.
Previous Comments:
------------------------------------------------------------------------
[2014-10-28 23:50:05] zf at ancientrock dot org
Description:
------------
While using str_replace to replace string (CP936 encoding), the result leading bad encoding text
output
Test script:
---------------
<?php
//GBK encoding str_replace test; save this file into GBK encoding and run it
$str =
"éå
ä¿å¹³å®ï¼ä½ å¿éæä¸èæçæ¶åå°±è¯´åºæ¥ï¼ä¸ºä»ä¹ä¸èæï¼å¥³å©å齿ç¹è¿æ ·çè¾æ°ç";
var_dump(str_replace('éå
', '**', $str));
Expected result:
----------------
display:
ä¿å¹³å®ï¼ä½ å¿éæä¸èæçæ¶åå°±è¯´åºæ¥ï¼ä¸ºä»ä¹ä¸èæï¼å¥³å©å齿ç¹è¿æ ·çè¾æ°ç
Actual result:
--------------
the text was broken, and can not readable
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68320&edit=1