#30424 [Opn->Bgs]: mysql_real_escape_string fails to escape a"b`c'd/e\f right

From: Date: Wed, 13 Oct 2004 21:26:24 +0000
Subject: #30424 [Opn->Bgs]: mysql_real_escape_string fails to escape a"b`c'd/e\f right
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-67555@lists.php.net to get a copy of this message
ID: 30424 User updated by: tomer at ivrit dot org dot il Reported By: tomer at ivrit dot org dot il -Status: Open +Status: Bogus Bug Type: MySQL related Operating System: Linux PHP Version: 5.0.1 New Comment: Sorry for the bother, bogus, won't happen again. Previous Comments: ------------------------------------------------------------------------ [2004-10-13 22:18:16] tomer at ivrit dot org dot il Sorry from all the testing I confused it up. It won't return an error but instead it will submit only the 'a' character and drop the rest of the string after it. ------------------------------------------------------------------------ [2004-10-13 21:42:46] tomer at ivrit dot org dot il Description: ------------ It seems that mysql_real_escape_string fails to escape the string 'a"b`c'd/e\f' (without the surrounding quotes) right.. Reproduce code: --------------- While magic_quotes_gpc are off and submitting on a POST form: a"b`c'd/e\f $query = sprintf("UPDATE tbl SET field='%s'", mysql_real_escape_string($_POST['name'])); $result = mysql_query($query); Expected result: ---------------- The mysql_error() will be a syntax error of course.. Actual result: -------------- You have an error in your SQL syntax near 'd/e\f', ... ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=30424&edit=1

« previous php.bugs (#67555) next »