RE: [PHP] magic_quotes_gpc
| From: | Lars Torben Wilson | Date: | Tue, 02 Jan 2001 21:48:08 +0000 |
| Subject: | RE: [PHP] magic_quotes_gpc | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-32368@lists.php.net to get a copy of this message | ||
Sam Masiello writes:
>
> Actually...to be more precise, it will automatically put quotes around all
> GET, POST, or cookie data. My apologies for the possible confusion!
Actually, it will not put quotes around any of the above. What it will
do it escape incoming data from the above sources if it contains
quotes or NULLs. It does this since often this kind of data needs to
go into a database, and having unescaped quotes can cause problems in
db calls.
For instance, if you put the following in a form field:
This isn't a test.
...then the actual value of the variable in your script will be:
This isn\'t a test.
This is only part of what it does; for the full story, check the
manual:
http://www.php.net/manual/configuration.php#ini.magic-quotes-gpc
Cheers,
Torben
> Sam Masiello
> Systems Analyst
> Chek.Com
> (716) 853-1362 x289
> smasiello@chekinc.com
>
> -----Original Message-----
> From: Jerry Lake [mailto:jerryl@europa.com]
> Sent: Tuesday, January 02, 2001 2:49 PM
> To: php-general@lists.php.net
> Subject: [PHP] magic_quotes_gpc
>
> what does magic_quotes_gpc do ?
>
> Jerry Lake
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+