PHP 4.0 Bug #8380 Updated: escaping problem with post vars
| From: | zak@php.net | Date: | Fri, 22 Dec 2000 20:37:15 +0000 |
| Subject: | PHP 4.0 Bug #8380 Updated: escaping problem with post vars | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42133@lists.php.net to get a copy of this message | ||
ID: 8380
Updated by: zak
Reported By: jeremy@kfx2.com
Old-Status: Open
Status: Closed
Bug Type: Scripting Engine problem
Assigned To:
Comments:
Dear Jeremy,
This behavior is not a bug and can be controlled via settings in the php.ini file. Specifically,
look for the magic_quotes_gpc directive.
You can also manually strip the slashes with the stripslashes function.
Zak
Previous Comments:
---------------------------------------------------------------------------
[2000-12-22 14:30:38] jeremy@kfx2.com
I'm working on a registration form that spans multiple pages. To keep track of some data
I'll output new inputs to retain the information across x amount of pages.
Well, on one field I retained, it held a character that is gets a backslash prepended to it (I
assume so it can be escaped later on). The char in question is a backslash, so I'd end up with
something like \.
In example, let's say I input a VB code explanation into a text box... "52 = 2"
(without the quotes of course).
I'd then output that to the next page after submission to a hidden input. On one submission
I'd end up with "5\2 = 2" which is normal. I can escape that; no problem.
But, after sending the submission across several pages it keeps on doubling. It is never escaped
before the backslash is prepended again. So, the next time I'd have "5\\2 = 2"
instead. The next time would be "5\\\\2 = 2" and so on.
If I spanned that across several pages and escaped it before I sent the data to a database or CGI or
something, I'll never get the original value.
Try the below script. Try clicking the submit button several times and see the output of the
variable. I know it gives an undefined variable warning (the first time only), but I was trying to
keep the script simple (KISS).
My environment...
OS - Microsoft Windows 2000 Professional w/ Service Pack 1
HTTP Server - Apache 1.3.14
PHP - PHP 4.04 (Built 12/20/00), CGI version.
-----------------------------------------------------------
<html>
<body>
<form method="post">
<? if ($escaped=="") $escaped="\"; ?>
<input type="hidden" name="escaped" value="<? echo $escaped;
?>">
<? echo $escaped; ?><p>
<input type="submit">
</form>
</body>
</html>
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8380