Bug #13701 Updated: mysql_escape_string() bugged
| From: | sander@php.net | Date: | Tue, 23 Oct 2001 18:24:05 +0000 |
| Subject: | Bug #13701 Updated: mysql_escape_string() bugged | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-68866@lists.php.net to get a copy of this message | ||
ID: 13701
Updated by: sander
Reported By: ed3f@phreaker.net
Old Status: Open
Status: Bogus
Bug Type: MySQL related
Operating System: OpenBSD 2.9
PHP Version: 4.0.6
New Comment:
Intended behaviour. You are doing something wrong.
You might have magic_quotes_runtime enabled in your php.ini
Previous Comments:
------------------------------------------------------------------------
[2001-10-16 19:57:08] ed3f@phreaker.net
mysql_escape_string() is bugged.
It escapes also '\'.
So if I make:
$string = 'Hi \dumb\ man';
$estring = mysql_escape_string($string);
now
$estring = 'Hi \\dumb\\ man';
So I put it in a cell
UPDATE ... SET string='.$estring.'
All ok ?
No!
If I try to SELECT I obtain
$estring not $string !
This is really annoying for public site powered by MySQL that accept comments.
Also PHP-Nuke have (had?) this problem.
Thanks.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13701&edit=1