Menu ▾ ▴

#2 MySQL error on submitting a quote with a ' in it

open
nobody
None
5
2005-12-15
2005-12-15
Anonymous
No

In add.inc.php the system is not currently cleaning
the submitted entry correctly before inserting it
into the database

/* Filter 'bad' characters from quote */
$newquote = htmlspecialchars("$newquote");
$newquote = nl2br($newquote);
$comment = htmlspecialchars("$comment");

Here the quote is cleaned, but your not taking care
of single quotes.

Should be

/* Filter 'bad' characters from quote */
$newquote = addslashes("$newquote");
$newquote = htmlspecialchars("$newquote");
$newquote = nl2br($newquote);
$comment = addslashes("$comment");
$comment = htmlspecialchars("$comment");

Should also take care of preping the comments too.

Discussion

  • Nobody/Anonymous

    Logged In: NO

    Thanks, theres actually a few places this should be added,
    i'll take a look at this tonight

     
  • Nobody/Anonymous

    Logged In: NO

    Just the first place I saw it and had a problem with it,
    I'm sure its possibly missing in other places as well.

     
  • Nobody/Anonymous

    Logged In: NO

    Any updates?

    Sorta wanting to go live, but didn't have time to browse
    over everything.

     

Log in to post a comment.