<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1029034" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1029034</link>
    <description></description>
    <language>en</language>
          <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170512</link>
    <description> &lt;p&gt;thanks, was just gonna write that i&#039;d figured out your last post. is the ENT-Quotes i had not been using as did not undertsand it&lt;/p&gt;
&lt;p&gt;grrr&lt;/p&gt;
&lt;p&gt;all sorted now at last - thanks&lt;/p&gt;
 </description>
     <pubDate>Mon, 02 May 2005 22:49:49 +0000</pubDate>
 <dc:creator>JP Stones</dc:creator>
 <guid isPermaLink="false">comment 1170512 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170511</link>
    <description> &lt;p&gt;sorry,&lt;/p&gt;
&lt;p&gt;replace addslashes($input_data) with htmlspecialchars($input_data, ENT_QUOTES) or htmlentities($input_data, ENT_QUOTES)&lt;/p&gt;
 </description>
     <pubDate>Mon, 02 May 2005 22:43:18 +0000</pubDate>
 <dc:creator>Busy</dc:creator>
 <guid isPermaLink="false">comment 1170511 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170508</link>
    <description> &lt;p&gt;i cant see where i would put these to make it work Busy?&lt;/p&gt;
&lt;p&gt;J&lt;/p&gt;
 </description>
     <pubDate>Mon, 02 May 2005 22:20:48 +0000</pubDate>
 <dc:creator>JP Stones</dc:creator>
 <guid isPermaLink="false">comment 1170508 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170451</link>
    <description> &lt;p&gt;you could use htmlspecialchars($var, ENT_QUOTES) or if you want more characters transverted use htmlentities($var, ENT_QUOTES)&lt;/p&gt;
&lt;p&gt;this is instead of addslashes and you wont need to use stripslashes as it converts the quotes - &quot; = &amp;amp;quot ; &#039; = &amp;amp;#039 ; etc&lt;/p&gt;
 </description>
     <pubDate>Sun, 01 May 2005 22:46:33 +0000</pubDate>
 <dc:creator>Busy</dc:creator>
 <guid isPermaLink="false">comment 1170451 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170441</link>
    <description> &lt;p&gt;ok more fiddling and I have it working for double quotes but still not for single quotes&lt;/p&gt;
&lt;p&gt;its passing the variable through the previw phase that is the problem. &lt;/p&gt;
&lt;p&gt;try running the script with a single quot ein it and it displays it fine in preview but cuts it on the hidden field so that it does not go through to the final stage.... ahhhhh&lt;/p&gt;
&lt;p&gt;it would be great of someone could take a look for me&lt;/p&gt;
&lt;p&gt;&lt;div class=&quot;codeblock&quot;&gt;&lt;code&gt;&lt;span style=&quot;color: #000000&quot;&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;&amp;lt;?php&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;color: #FF8000&quot;&gt;// display form if first time on page&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;if (&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_GET&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;stage&#039;&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;] == \&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&quot;start\&quot;)&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo \&quot;Collect Data:&amp;lt;br&amp;gt;\&quot;;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo \&quot;&amp;lt;form action=&#039;preview.php?stage=preview&#039; method=&#039;post&#039;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input name=&#039;form_field&#039; type=&#039;text&#039;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type=&#039;submit&#039; value=&#039;Preview Entry&#039; class=&#039;button&#039;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/form&amp;gt;\&quot;;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;// display preview on submit&lt;br /&gt;&lt;br /&gt;if (@&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_GET&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;stage&#039;] == \&quot;preview\&quot;)&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_REQUEST&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;form_field&#039;];&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if(get_magic_quotes_gpc()) &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; {&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = stripslashes(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo \&quot;Preview Data:&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;\&quot;;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo \&quot;&amp;lt;br&amp;gt;&amp;lt;form action=&#039;preview.php?stage=end&#039; method=&#039;post&#039;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type=&#039;text&#039; name=&#039;form_field&#039; value=&#039;&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type=&#039;submit&#039; value=&#039;Add Entry&#039;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/form&amp;gt;\&quot;;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;// display confirmation page and submit to database&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;if (&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_GET&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;stage&#039;] == \&quot;end\&quot;)&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_REQUEST&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;form_field&#039;]; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = addslashes(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$query&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = \&quot;insert into element (element) values (&#039;&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$input_data&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;)\&quot;;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$result&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = mysql_query(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$query&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;) or die (\&quot;Couldn&#039;t execute query.\&quot;);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo \&quot;Your text has been inserted into the database. &amp;lt;a href=&#039;preview.php?stage=show&#039;&amp;gt;View&amp;lt;/a&amp;gt;\&quot;; &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;if (&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$_GET&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;stage&#039;] == \&quot;show\&quot;)&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$query&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = \&quot;select element from element\&quot;;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$result&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = mysql_query(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$query&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;) or die (\&quot;Couldn&#039;t execute query.\&quot;);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$row&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = mysql_fetch_array(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$result&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$element&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt; = stripslashes(&lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$row&lt;/span&gt;&lt;span style=&quot;color: #007700&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;&#039;element&#039;]);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; echo &lt;/span&gt;&lt;span style=&quot;color: #0000BB&quot;&gt;$element&lt;/span&gt;&lt;span style=&quot;color: #DD0000&quot;&gt;;&lt;br /&gt;}&lt;br /&gt;?&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;
&lt;p&gt;JP&lt;/p&gt;
 </description>
     <pubDate>Sun, 01 May 2005 17:47:09 +0000</pubDate>
 <dc:creator>JP Stones</dc:creator>
 <guid isPermaLink="false">comment 1170441 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170179</link>
    <description> &lt;p&gt;addslashes into the database&lt;br /&gt;
stripslashes from info out of database&lt;/p&gt;
&lt;p&gt;You can reverse the quotes in the form variable: $form1 = &#039;&lt;br /&gt;
I perfer this method so it can still be validated&lt;/p&gt;
 </description>
     <pubDate>Tue, 26 Apr 2005 21:46:11 +0000</pubDate>
 <dc:creator>Busy</dc:creator>
 <guid isPermaLink="false">comment 1170179 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/serverside-scripting/quote-problems-php#comment-1170172</link>
    <description> &lt;p&gt;I hate to point you at a competing forum, but look at the second post here:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.sitepoint.com/forums/showthread.php?t=257556&quot; class=&quot;bb-url&quot;&gt;http://www.sitepoint.com/forums/showthread.php?t=257556&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It has a perfect summary of the code used for each step.  In particular, I think you want addslashes, not stripslashes.  But review the example at Sitepoint.&lt;/p&gt;
&lt;p&gt;-Tony&lt;/p&gt;
 </description>
     <pubDate>Tue, 26 Apr 2005 18:55:33 +0000</pubDate>
 <dc:creator>aboyd</dc:creator>
 <guid isPermaLink="false">comment 1170172 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
