Bug #13520: Wrong handling of the escape characters.
| From: | mcdouglas at angelfire dot com | Date: | Tue, 02 Oct 2001 20:06:41 +0000 |
| Subject: | Bug #13520: Wrong handling of the escape characters. | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-67111@lists.php.net to get a copy of this message | ||
From: mcdouglas@angelfire.com
Operating system:
PHP version: 4.0.6
PHP Bug Type: Output Control
Bug description: Wrong handling of the escape characters.
In a html: <a href="test.php?str=some'thing">test</a>
And the test.php:
<?
echo $str;
?>
I used the win32 binary version of the php.
In the link I put the "some'thing" into the str variable whivh will pass to
the script if i click on the Testlink.
I read in the manual the ' " \ are special character, and I must escape
them with a \. Ok, I didn't used the \ before the ' in the something text,
so I think the normal is that I get some error message...
But no: thw script will output the "some\'thing" text... which are funy
because if I put the $str into a database (with a mysql_query) it will
contain the original text: some'thing.
And if I use the \ in my link (like this: test.php?str=some\'thing) then
the script will output the "some\\\'thing"... But I think it must output
the "some'thing" because I used the \ before the '.
So, could be this a bug? I think so...
--
Edit bug report at: http://bugs.php.net/?id=13520&edit=1