php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #8380 escaping problem with post vars
Submitted: 2000-12-22 14:30 UTC Modified: 2000-12-22 15:37 UTC
From: jeremy at kfx2 dot com Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.0.4 OS: Windows 2000 Pro., SP1
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: jeremy at kfx2 dot com
New email:
PHP Version: OS:

 

 [2000-12-22 14:30 UTC] jeremy at kfx2 dot com
I'm working on a registration form that spans multiple pages.  To keep track of some data I'll output new inputs to retain the information across x amount of pages.

Well, on one field I retained, it held a character that is gets a backslash prepended to it (I assume so it can be escaped later on).  The char in question is a backslash, so I'd end up with something like \\.

In example, let's say I input a VB code explanation into a text box... "5\2 = 2" (without the quotes of course).

I'd then output that to the next page after submission to a hidden input.  On one submission I'd end up with "5\\2 = 2" which is normal.  I can escape that; no problem.

But, after sending the submission across several pages it keeps on doubling.  It is never escaped before the backslash is prepended again.  So, the next time I'd have "5\\\\2 = 2" instead.  The next time would be "5\\\\\\\\2 = 2" and so on.

If I spanned that across several pages and escaped it before I sent the data to a database or CGI or something, I'll never get the original value.

Try the below script.  Try clicking the submit button several times and see the output of the variable.  I know it gives an undefined variable warning (the first time only), but I was trying to keep the script simple (KISS).

My environment...
OS - Microsoft Windows 2000 Professional w/ Service Pack 1
HTTP Server - Apache 1.3.14
PHP - PHP 4.04 (Built 12/20/00), CGI version.

-----------------------------------------------------------

<html>
<body>
<form method="post">
<? if ($escaped=="") $escaped="\\"; ?>
<input type="hidden" name="escaped" value="<? echo $escaped; ?>">
<? echo $escaped; ?><p>
<input type="submit">
</form>
</body>
</html>

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-12-22 15:37 UTC] zak@php.net
Dear Jeremy,

This behavior is not a bug and can be controlled via settings in the php.ini file.  Specifically, look for the magic_quotes_gpc directive.

You can also manually strip the slashes with the stripslashes function.

Zak
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 13:00:01 2026 UTC