Author |
Message |
LostGhost
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Mar 29, 2004
Posts: 5
|
Posted:
Mon Mar 29, 2004 2:05 pm |
|
Every time someone uses an apostrophe when posting a news story / review / etc, nuke appears to be inserting a \.
So (for example) if they were to submit the word don't, it would be changed to don\'t
Please help as this is driving me mad.
As this is happening everywhere that someone can submit to the site I assume this is being caused by one of the core pages. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/6c868/6c86859170a3596c942592f58366e4a982a03ad0" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Mon Mar 29, 2004 2:25 pm |
|
That is a security precaution. addslashes() is the function and prevents XSS attacks. The data should be stored in the database but the stripped out with stripslashes() before being displayed. Are you saying that it is actually displaying the \' in your news article? If so, this is not the behavior of the native News module. have you applied any code changes to your News module? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
LostGhost
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 2:45 pm |
|
Thats exactly what I'm saying, and I haven't made any changes to the native News module (though I have edited some of the others).
However, this problem isn't confined to News.
It happens in every module people can submit (i.e. reviews, comments in Coppermine, etc.).
Thats why I presumed there was something missing from one of the core files. Does the stripslash appear in something like mainfile.php ? |
Last edited by LostGhost on Mon Mar 29, 2004 3:07 pm; edited 1 time in total |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 2:54 pm |
|
Just for curiosity, run phpinfo() and check this setting:
magic_quotes_gpc
Is it set to On or Off? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
LostGhost
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 3:08 pm |
|
magic_quotes_gpc On
magic_quotes_runtime Off
magic_quotes_sybase Off |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 3:12 pm |
|
If you have not made any changes at all, then I would suggest reuploading all files, as a first step. What version of nuke and MySQL are you using? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
LostGhost
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 3:23 pm |
|
As per title, it is Nuke 7.0
I downloaded it from the club when it first became available, although I only started noticing the / problem after installing Coppermine (but it could have been there before).
I have been applying security patches and fixes as they became available, so I am rather loath to over-write everything by uploading the files. Would I be better off upgrading to 7.1 or 7.2?
It is running on MySQL 4.0.18-standard |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 3:26 pm |
|
7.2 for sure. Coppermine is wrecking some havoc right now on many sites so I would be suspicious .... |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
LostGhost
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 29, 2004 4:05 pm |
|
OK I'll get 7.2 Final and try updating to that.
I'll let you know how I get on.
Thanks for your help. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|