Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Question about escape characters in DB
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Question about escape characters in DB

 Post Reply Post Reply
Author
Jyn13 View Drop Down
Newbie
Newbie


Joined: 01 June 2005
Location: United States
Status: Offline
Points: 7
Post Options Post Options   Thanks (0) Thanks(0)   Quote Jyn13 Quote  Post ReplyReply Direct Link To This Post Topic: Question about escape characters in DB
    Posted: 09 May 2008 at 7:34pm
Hello,
 
As near as I could tell this hasn't been asked before, but as far as I know it could be unique to my specific hardware/software setup too. Anyways, I was looking at the database working on a plan for how I'm going to integrate it into my existing membership setup and modifying the registration form and all that.
 
In some of the fields (but not consistently across records) escape characters show instead of the o the & # 111; (spaces put in so it displays and doesn't convert) it displays properly on the webpages, I'm just curious why this is happening so I make sure I pass info to the database correctly with my modified registration page.
I'm running Windows Server 2003, IIS 6.0, SQL Server 2005 and using IE 7, with Version 9.08 of the forum.
 
Jyn
 
edit/update: after working with the DBA at work to see if she could help me explain it, it looks like it only coverts the o to the escape sequence when it would say "on" in the field.
So what I need to know, is this a SQL thing or an app thing?


Edited by Jyn13 - 09 May 2008 at 7:37pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 12 May 2008 at 10:11am
The security filters do this when you submit the page.

The reason is that many scripting and css malicious code is fired by on events, such as 'onmouseover', 'onload', etc. To prevent malicious code getting through the word 'on' is HTML encoded which prevents allot of malicious code from running.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.