note 27853 added to function.addslashes
| From: | thebitman at attbi dot com | Date: | Sat, 21 Dec 2002 06:36:48 +0000 |
| Subject: | note 27853 added to function.addslashes | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-41170@lists.php.net to get a copy of this message | ||
there is a function mentioned above which I will call "addslashes_once()", it is posted
anonymously. DO NOT USE THAT FUNCTION!
first, look at the code:
addslashes_once($str) {
if((string)stripslashes($str) === (string)$str)
return addslashes($str);
else return $str;
}
Now, consider what it would do with this:
"\\' LIMIT 1; DELETE FROM
records WHERE 1"
oops.
Yes, it's annoying that addslashes will add to something already slashed, but remember that it
does that for a reason! There is no way to know if a string has been slashed or not unless you just
do what I do: Just plain disallow the \ from anything that will be used to look something up. For
many purposes that is way too restrictive, so it's best to take the hard road, and just keep
track of your addslashes() usage.
--
http://www.php.net/manual/en/function.addslashes.php
http://master.php.net/manage/user-notes.php?action=edit+27853
http://master.php.net/manage/user-notes.php?action=delete+27853
http://master.php.net/manage/user-notes.php?action=reject+27853