PHP 4.0 Bug #6625: htmlspecialchars should escape "'" character

From: Date: Fri, 08 Sep 2000 10:19:59 +0000
Subject: PHP 4.0 Bug #6625: htmlspecialchars should escape "'" character
Groups: php.dev 
Request: Send a blank email to php-dev+get-32645@lists.php.net to get a copy of this message
From: jon+php-dev@unequivocal.co.uk Operating system: N/A PHP version: 4.0 Latest CVS (08/09/2000) PHP Bug Type: *Function Specific Bug description: htmlspecialchars should escape "'" character Please first see bug report #5254. Either this function should not escape '"', or it *should* escape "'". These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2 . If you do not escape "'", then the following will not work: <input type='hidden' name='foo' value='<? echo htmlspecialchars($foo) ?>'> Please do not tell me that the above HTML is not valid without reading the URL I have given first. I do not understand the arguments put in #5254 about databases. What has this function got to do with databases?

« previous php.dev (#32645) next »