PHP 4.0 Bug #8380: escaping problem with post vars

From: Date: Fri, 22 Dec 2000 19:30:38 +0000
Subject: PHP 4.0 Bug #8380: escaping problem with post vars
Groups: php.dev 
Request: Send a blank email to php-dev+get-42131@lists.php.net to get a copy of this message
From: jeremy@kfx2.com Operating system: Windows 2000 Pro., SP1 PHP version: 4.0.4 PHP Bug Type: Scripting Engine problem Bug description: escaping problem with post vars I'm working on a registration form that spans multiple pages. To keep track of some data I'll output new inputs to retain the information across x amount of pages. Well, on one field I retained, it held a character that is gets a backslash prepended to it (I assume so it can be escaped later on). The char in question is a backslash, so I'd end up with something like \\. In example, let's say I input a VB code explanation into a text box... "5\2 = 2" (without the quotes of course). I'd then output that to the next page after submission to a hidden input. On one submission I'd end up with "5\\2 = 2" which is normal. I can escape that; no problem. But, after sending the submission across several pages it keeps on doubling. It is never escaped before the backslash is prepended again. So, the next time I'd have "5\\\\2 = 2" instead. The next time would be "5\\\\\\\\2 = 2" and so on. If I spanned that across several pages and escaped it before I sent the data to a database or CGI or something, I'll never get the original value. Try the below script. Try clicking the submit button several times and see the output of the variable. I know it gives an undefined variable warning (the first time only), but I was trying to keep the script simple (KISS). My environment... OS - Microsoft Windows 2000 Professional w/ Service Pack 1 HTTP Server - Apache 1.3.14 PHP - PHP 4.04 (Built 12/20/00), CGI version. ----------------------------------------------------------- <html> <body> <form method="post"> <? if ($escaped=="") $escaped="\\"; ?> <input type="hidden" name="escaped" value="<? echo $escaped; ?>"> <? echo $escaped; ?><p> <input type="submit"> </form> </body> </html> -- Edit Bug report at: http://bugs.php.net/?id=8380&edit=1

« previous php.dev (#42131) next »