Re: PHP 4.0 Bug #7630: ereg_replace or preg_replace
| From: | Ignacio Vazquez-Abrams | Date: | Fri, 03 Nov 2000 23:45:17 +0000 |
| Subject: | Re: PHP 4.0 Bug #7630: ereg_replace or preg_replace | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-37043@lists.php.net to get a copy of this message | ||
On 3 Nov 2000 bmonro@ccbill.com wrote:
> From: bmonro@ccbill.com
> Operating system: freeBSD
> PHP version: 4.0.3pl1
> PHP Bug Type: Unknown/Other Function
> Bug description: ereg_replace or preg_replace
>
> I have an HTML text input field generated by my php code:
> print "<input type=text name=varname>";
>
> the script is accepting the input just fine.
>
> I then need to pass the variable into a mysql database query.
>
> This is where it barfs.
>
> it is putting backslashes before any single quotes i put in the text field. So I tried using
> ereg_replace and preg_replace to replace the backslash with nothing (i.e. empty string). but to no
> avail
>
> here is what happens:
>
> if I type this in the input box:
>
> login_id = 'username'
>
> it sends this to the mysql query:
> login_id = \'username\'
>
> ereg_replace and preg_replace are both getting messed up on the backslash.
>
> PLEASE HELP!
>
Turn off magic_quotes_gpc in your php.ini, then make sure that the rest of
your scripts work. agic_quotes_gpc is useful for some things, but as
you've discovered, it can be a real PITA most of the time.
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>