RE: [PHP] Strings in text fields are bad
| From: | Maxim Maletsky | Date: | Tue, 26 Sep 2000 05:34:45 +0000 |
| Subject: | RE: [PHP] Strings in text fields are bad | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17529@lists.php.net to get a copy of this message | ||
I knew that, but if you use in your script ' all the time then it will work
OK, this kinda errors are happening on PHP3 which on GEt and POST does
nothing but trully gives you the variable's values.
PHP 4 filters any input with adslashes(), in fact you'll never get the staff
like _don't_ just as you see it here: it will add a backslash infront _ ' _
Cheers!
-----Original Message-----
From: Simon Edwards [mailto:simon@animated.net.au]
Sent: Tuesday, September 26, 2000 1:49 PM
To: Maxim Maletsky
Cc: php-general@lists.php.net
Subject: Re: [PHP] Strings in text fields are bad
Maxim Maletsky wrote:
> well, just tested:
>
> $caddress = "12345 'Abc Ave.";
> echo '<input type=text name=caddress value="' . $caddress .
> '">';
>
> not much happens ...
Try $caddress = '1234 "Abc Ave';
or $caddress = "1234 Abc Ave\"><SCRIPT
language=\"JavaScript\">alert('Boo');</SCRIPT>";
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990