RE: [PHP] Strings in text fields are bad
| From: | Lawrence dot Sheed at dfait-maeci dot gc dot ca | Date: | Tue, 26 Sep 2000 06:00:41 +0000 |
| Subject: | RE: [PHP] Strings in text fields are bad | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17531@lists.php.net to get a copy of this message | ||
We should clarify ;)
If you use ' as a separator then having a ' in your output will break the
html
If you use " as a separator then having a " in your output will break the
html
Eg:
$stuff = 'nasty"person';
echo '<name=stuff value='" . $stuff '">'; is ok
but
$stuff = "nasty'person";
echo '<name=stuff value='" . $stuff '">'; is not
Won't break the php, just the html output.
Thats why you always validate + htmlspecialchars it.
BTW
htmlspecialchars has an additional option to trap 's, but it only works on
the "new" version of php4.
Have a look at htmlspecialchars in the manual on php.net for details.
cheers,
Lawrence.
-----Original Message-----
From: Simon Edwards [mailto:simon@animated.net.au]
Sent: September 26, 2000 12:52 PM
To: Lawrence.Sheed@dfait-maeci.gc.ca
Cc: php-general@lists.php.net
Subject: Re: [PHP] Strings in text fields are bad
Lawrence.Sheed@dfait-maeci.gc.ca wrote:
> I was paranoid too ;)
perhaps not paranoid enough.
> See my example mail earlier.
> $caddress=stripslashes ( htmlspecialchars("12345 Abc Ave."));
$caddress = htmlspecialchars(stripslashes("12345 Abc Ave."));
:-)
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net