PHP 4.0 Bug #6625: htmlspecialchars should escape "'" character
| From: | jon+php-dev at unequivocal dot co dot uk | Date: | Fri, 08 Sep 2000 10:19:59 +0000 |
| Subject: | PHP 4.0 Bug #6625: htmlspecialchars should escape "'" character | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32645@lists.php.net to get a copy of this message | ||
From: jon+php-dev@unequivocal.co.uk
Operating system: N/A
PHP version: 4.0 Latest CVS (08/09/2000)
PHP Bug Type: *Function Specific
Bug description: htmlspecialchars should escape "'" character
Please first see bug report #5254.
Either this function should not escape '"', or it *should* escape "'".
These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2
.
If you do not escape "'", then the following will not work:
<input type='hidden' name='foo' value='<? echo htmlspecialchars($foo)
?>'>
Please do not tell me that the above HTML is not valid without reading the URL I have given first.
I do not understand the arguments put in #5254 about databases. What has this function got to do
with databases?