Bug #13701: mysql_escape_string() bugged
| From: | ed3f at phreaker dot net | Date: | Tue, 16 Oct 2001 23:57:08 +0000 |
| Subject: | Bug #13701: mysql_escape_string() bugged | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-68082@lists.php.net to get a copy of this message | ||
From: ed3f@phreaker.net
Operating system: OpenBSD 2.9
PHP version: 4.0.6
PHP Bug Type: MySQL related
Bug description: mysql_escape_string() bugged
mysql_escape_string() is bugged.
It escapes also '\'.
So if I make:
$string = 'Hi \dumb\ man';
$estring = mysql_escape_string($string);
now
$estring = 'Hi \\dumb\\ man';
So I put it in a cell
UPDATE ... SET string='.$estring.'
All ok ?
No!
If I try to SELECT I obtain
$estring not $string !
This is really annoying for public site powered by MySQL that accept
comments.
Also PHP-Nuke have (had?) this problem.
Thanks.
--
Edit bug report at: http://bugs.php.net/?id=13701&edit=1