Bug #4123: rawurlencode() is not RFC1738-complient
| From: | martin at inmeco dot de | Date: | Wed, 12 Apr 2000 23:58:07 +0000 |
| Subject: | Bug #4123: rawurlencode() is not RFC1738-complient | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-17854@lists.php.net to get a copy of this message | ||
From: martin@inmeco.de
Operating system: Linux / Windows NT
PHP version: 3.0.15
PHP Bug Type: Misbehaving function
Bug description: rawurlencode() is not RFC1738-complient
rawurlencode() does not convert the '%' character to '%25' althought this
character is specified in RFC1738 as unsafe thus it has to be converted to '%25'.
This is a serious leak if you use rawurlencode() and rawurldecode().
For example the code snippet
$a = rawurlencode("%berg%");
print rawurldecode($a);
produces a
¾rg%
instead of
%berg%
Since I've been using rawurlencode()/rawurldecode() pairs in many different scripts that work
on a lot of different sites I sit on a bomb now because I don't know when the first character
string like '%be' or '%12' will be misinterpreted.
BTW: How about founding rawurlencode() on the more accurate RFC2396 that on 1738?
Bye
Martin Kadlec