diff options
| author | Ilia Alshanetsky <iliaa@php.net> | 2006-12-08 17:50:04 +0000 |
|---|---|---|
| committer | Ilia Alshanetsky <iliaa@php.net> | 2006-12-08 17:50:04 +0000 |
| commit | db7dad0ba0fbb4428be3477b1ce670d3acb82b6e (patch) | |
| tree | 82e41e0b9651966b9263e32f09b3bf979d0143c5 /ext/filter | |
| parent | cdf5db41a724d428b80f775187ac97bec0580244 (diff) | |
| download | php-git-db7dad0ba0fbb4428be3477b1ce670d3acb82b6e.tar.gz | |
Fixed bug #39763 (magic quotes are applied twice by ext/filter in
parse_str())
Diffstat (limited to 'ext/filter')
| -rw-r--r-- | ext/filter/filter.c | 2 | ||||
| -rw-r--r-- | ext/filter/tests/bug39763.phpt | 15 |
2 files changed, 16 insertions, 1 deletions
diff --git a/ext/filter/filter.c b/ext/filter/filter.c index 1b87db2e2d..b2107aaa00 100644 --- a/ext/filter/filter.c +++ b/ext/filter/filter.c @@ -397,7 +397,7 @@ static unsigned int php_sapi_filter(int arg, char *var, char **val, unsigned int Z_STRVAL(new_var) = estrndup(*val, val_len); INIT_PZVAL(tmp_new_var); php_zval_filter(&tmp_new_var, IF_G(default_filter), IF_G(default_filter_flags), NULL, NULL/*charset*/, 0 TSRMLS_CC); - } else if (PG(magic_quotes_gpc)) { + } else if (PG(magic_quotes_gpc) && !retval) { /* for PARSE_STRING php_register_variable_safe() will do the addslashes() */ Z_STRVAL(new_var) = php_addslashes(*val, Z_STRLEN(new_var), &Z_STRLEN(new_var), 0 TSRMLS_CC); } else { Z_STRVAL(new_var) = estrndup(*val, val_len); diff --git a/ext/filter/tests/bug39763.phpt b/ext/filter/tests/bug39763.phpt new file mode 100644 index 0000000000..e09afd7d5b --- /dev/null +++ b/ext/filter/tests/bug39763.phpt @@ -0,0 +1,15 @@ +--TEST-- +Bug #39763 filter applies magic_quotes twice in parse_str() +--INI-- +magic_quotes_gpc=1 +--FILE-- +<?php +$arr = array(); +parse_str("val=%22probably+a+bug%22", $arr); +echo $arr['val'] . "\n"; +parse_str("val=%22probably+a+bug%22"); +echo $val . "\n"; +?> +--EXPECT-- +\"probably a bug\" +\"probably a bug\" |
