php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #8380 escaping problem with post vars
Submitted: 2000-12-22 14:30 UTC Modified: 2000-12-22 15:37 UTC
From: jeremy at kfx2 dot com Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.0.4 OS: Windows 2000 Pro., SP1
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: jeremy at kfx2 dot com
New email:
PHP Version: OS:

 

 [2000-12-22 14:30 UTC] jeremy at kfx2 dot com
I'm working on a registration form that spans multiple pages.  To keep track of some data I'll output new inputs to retain the information across x amount of pages.

Well, on one field I retained, it held a character that is gets a backslash prepended to it (I assume so it can be escaped later on).  The char in question is a backslash, so I'd end up with something like \\.

In example, let's say I input a VB code explanation into a text box... "5\2 = 2" (without the quotes of course).

I'd then output that to the next page after submission to a hidden input.  On one submission I'd end up with "5\\2 = 2" which is normal.  I can escape that; no problem.

But, after sending the submission across several pages it keeps on doubling.  It is never escaped before the backslash is prepended again.  So, the next time I'd have "5\\\\2 = 2" instead.  The next time would be "5\\\\\\\\2 = 2" and so on.

If I spanned that across several pages and escaped it before I sent the data to a database or CGI or something, I'll never get the original value.

Try the below script.  Try clicking the submit button several times and see the output of the variable.  I know it gives an undefined variable warning (the first time only), but I was trying to keep the script simple (KISS).

My environment...
OS - Microsoft Windows 2000 Professional w/ Service Pack 1
HTTP Server - Apache 1.3.14
PHP - PHP 4.04 (Built 12/20/00), CGI version.

-----------------------------------------------------------

<html>
<body>
<form method="post">
<? if ($escaped=="") $escaped="\\"; ?>
<input type="hidden" name="escaped" value="<? echo $escaped; ?>">
<? echo $escaped; ?><p>
<input type="submit">
</form>
</body>
</html>

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-12-22 15:37 UTC] zak@php.net
Dear Jeremy,

This behavior is not a bug and can be controlled via settings in the php.ini file.  Specifically, look for the magic_quotes_gpc directive.

You can also manually strip the slashes with the stripslashes function.

Zak
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 20:00:02 2026 UTC