home | articles | links | fun | about
Up to: Quick math and science observations

more PHP security

anything which interprets HTML will have < text > be empty...


because magic_quotes are ON,

        " becomes =>

so we need to stripslashes and do HTML special chars before displaying data back.

user inputs "

becomes \"

addslashes sees this as two special characters, and it becomes \\+\" or \\\"

do a view source to see how htmlspecialchars converts it to "e, etc.