Bug #75163 [NEW]: filter_var with FILTER_SANITIZE_SPECIAL_CHARS is manipulating data

From: Date: Wed, 06 Sep 2017 11:07:53 +0000
Subject: Bug #75163 [NEW]: filter_var with FILTER_SANITIZE_SPECIAL_CHARS is manipulating data
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210971@lists.php.net to get a copy of this message
From: itsursujit at gmail dot com Operating system: Ubuntu PHP version: 5.6.31 Package: Filter related Bug Type: Bug Bug description:filter_var with FILTER_SANITIZE_SPECIAL_CHARS is manipulating data Description: ------------ I encountered this issue when I tried to sanitize urlencoded variables. Here are the steps with expected and actual results: Step 1: assign string to variable with encoded characters $x="I&#39;ve some comment"; Step 2: decode the variable using urldecode() $decoded=urldecode($x); //result: I've some comment; echo $decoded; EXPECTED RESULT: I've some comment ACTUAL RESULT: I've some comment Step 3: filter above decoded data and echo the result echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS)); EXPECTED RESULT: I've some comment ACTUAL RESULT: I&#39;ve some comment Step 4: filter above raw string and echo the result echo trim(filter_var(stripslashes("I've some comment"), FILTER_SANITIZE_SPECIAL_CHARS)); EXPECTED RESULT: I've some comment ACTUAL RESULT: I've some comment I think the Step 3 has some bug. Test script: --------------- <?php $x="I&#39;ve some comment"; $decoded=urldecode($x); //result: I've some comment; echo $decoded; //result: I've some comment; echo "\n"; echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS)); echo "\n"; echo trim(filter_var(stripslashes("I've some comment"), FILTER_SANITIZE_SPECIAL_CHARS)); Expected result: ---------------- $x="I&#39;ve some comment"; $decoded=urldecode($x); //result: I've some comment; echo $decoded; EXPECTED RESULT: I've some comment echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS)); EXPECTED RESULT: I've some comment echo trim(filter_var(stripslashes("I've some comment"), FILTER_SANITIZE_SPECIAL_CHARS)); EXPECTED RESULT: I've some comment Actual result: -------------- $x="I&#39;ve some comment"; $decoded=urldecode($x); //result: I've some comment; echo $decoded; ACTUAL RESULT: I've some comment echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS)); ACTUAL RESULT: I&#39;ve some comment echo trim(filter_var(stripslashes("I've some comment"), FILTER_SANITIZE_SPECIAL_CHARS)); ACTUAL RESULT: I've some comment -- Edit bug report at https://bugs.php.net/bug.php?id=75163&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75163&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75163&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75163&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75163&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75163&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75163&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75163&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75163&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75163&r=support Expected behavior: https://bugs.php.net/fix.php?id=75163&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75163&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75163&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75163&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75163&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75163&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75163&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75163&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75163&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75163&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75163&r=mysqlcfg

« previous php.bugs (#210971) next »