note 61400 deleted from function.strpos by danbrown
| From: | danbrown@php.net | Date: | Sun, 17 May 2009 16:36:35 +0000 |
| Subject: | note 61400 deleted from function.strpos by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-154863@lists.php.net to get a copy of this message | ||
Note Submitter: anonymous at example dot com
----
Beware of following the examples too closely...
$str = "abcdef";
echo strpos($str, 'b'); // outputs 1
however
$str = "abc\nef";
echo strpos($str, '\n'); // output nothing (FALSE)
Not a great way to try to stop PHP email injection attacks (as I found out).
Instead use
strpos($str, "\n")
because the escapes are processed only when using double quotes.