php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68320 str_replace not binary safe
Submitted: 2014-10-28 23:50 UTC Modified: 2014-10-29 00:12 UTC
From: zf at ancientrock dot org Assigned:
Status: Not a bug Package: Scripting Engine problem
PHP Version: 5.6.2 OS: CentOS 6.5 x64
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: zf at ancientrock dot org
New email:
PHP Version: OS:

 

 [2014-10-28 23:50 UTC] zf at ancientrock dot org
Description:
------------
While using str_replace to replace string (CP936 encoding), the result leading bad  encoding text output



Test script:
---------------
<?php

//GBK encoding str_replace test; save this file into GBK encoding and run it
$str = "退党保平安,你心里有不舒服的时候就说出来,为什么不舒服,女孩子都有点这样的脾气的";
var_dump(str_replace('退党', '**', $str));

Expected result:
----------------
display:
保平安,你心里有不舒服的时候就说出来,为什么不舒服,女孩子都有点这样的脾气的

Actual result:
--------------
the text was broken, and can not readable

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-10-29 00:12 UTC] requinix@php.net
-Status: Open +Status: Not a bug
 [2014-10-29 00:12 UTC] requinix@php.net
str_replace() is binary-safe. The problem is that the encoding you're using is not safe for writing PHP code in*, and in fact you'll get similar problems with other programming languages. GBK with a database can even expose you to SQL injection.

You need to use something other than GBK for your code. Like UTF-8 or -16.

* Briefly, GBK will encode some characters into \xHH\x5C (ie, a byte followed by a \x5C byte). \x5C is a backslash and that can cause problems because it's used for escape sequences in strings.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 21:00:01 2026 UTC