php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68320 str_replace not binary safe
Submitted: 2014-10-28 23:50 UTC Modified: 2014-10-29 00:12 UTC
From: zf at ancientrock dot org Assigned:
Status: Not a bug Package: Scripting Engine problem
PHP Version: 5.6.2 OS: CentOS 6.5 x64
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: zf at ancientrock dot org
New email:
PHP Version: OS:

 

 [2014-10-28 23:50 UTC] zf at ancientrock dot org
Description:
------------
While using str_replace to replace string (CP936 encoding), the result leading bad  encoding text output



Test script:
---------------
<?php

//GBK encoding str_replace test; save this file into GBK encoding and run it
$str = "退党保平安,你心里有不舒服的时候就说出来,为什么不舒服,女孩子都有点这样的脾气的";
var_dump(str_replace('退党', '**', $str));

Expected result:
----------------
display:
保平安,你心里有不舒服的时候就说出来,为什么不舒服,女孩子都有点这样的脾气的

Actual result:
--------------
the text was broken, and can not readable

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-10-29 00:12 UTC] requinix@php.net
-Status: Open +Status: Not a bug
 [2014-10-29 00:12 UTC] requinix@php.net
str_replace() is binary-safe. The problem is that the encoding you're using is not safe for writing PHP code in*, and in fact you'll get similar problems with other programming languages. GBK with a database can even expose you to SQL injection.

You need to use something other than GBK for your code. Like UTF-8 or -16.

* Briefly, GBK will encode some characters into \xHH\x5C (ie, a byte followed by a \x5C byte). \x5C is a backslash and that can cause problems because it's used for escape sequences in strings.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 23:00:02 2026 UTC