php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #18276 session_start with use_trans_sid adds unexpected quotes
Submitted: 2002-07-11 09:47 UTC Modified: 2002-07-11 10:28 UTC
From: kafka at antichri dot st Assigned:
Status: Not a bug Package: Session related
PHP Version: 4.1.2 OS: RedHat GNU/Linux 7.3
Private report: No CVE-ID: None
 [2002-07-11 09:47 UTC] kafka at antichri dot st
This may be related to bug #14080.

This bug is reproducible on 4.1.2 and 4.2.1, and can be seen using the following code:

<?
session_start();
print "<A HREF='http://foobar' onMouseIn=t('test')>test</A>";
?>

When cookies are not in use (eg. when first visiting the page in a new browser window), the following output results:

<A HREF='http://foobar' onMouseIn="t("'test')>test</A>

When cookies are used, the output is normal.

If session_start, the output is also normal.

Putting the link outside the <??> php code produces no change in the result.

All magic_quote options are disabled in php.ini

Configure line is as follows:

 './configure' 'i386-redhat-linux' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib' '--libexecdir=/usr/libexec' '--localstatedir=/var' '--sharedstatedir=/usr/com' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--prefix=/usr' '--with-config-file-path=/etc' '--enable-force-cgi-redirect' '--disable-debug' '--enable-dbg=shared' '--with-dbg-profiler' '--enable-pic' '--disable-rpath' '--enable-inline-optimization' '--with-bz2' '--with-db3' '--with-curl' '--with-dom=/usr' '--with-exec-dir=/usr/bin' '--with-freetype-dir=/usr' '--with-png-dir=/usr' '--with-gd' '--enable-gd-native-ttf' '--with-ttf' '--with-gdbm' '--with-gettext' '--with-ncurses' '--with-gmp' '--with-iconv' '--with-jpeg-dir=/usr' '--with-mm' '--with-openssl' '--with-png' '--with-pspell' '--with-regex=system' '--with-xml' '--with-expat-dir=/usr' '--with-zlib' '--with-layout=GNU' '--enable-bcmath' '--enable-debugger' '--enable-exif' '--enable-ftp' '--enable-magic-quotes' '--enable-safe-mode' '--enable-sockets' '--enable-sysvsem' '--enable-sysvshm' '--enable-discard-path' '--enable-track-vars' '--enable-trans-sid' '--enable-yp' '--enable-wddx' '--without-oci8' '--with-imap=shared' '--with-imap-ssl' '--with-kerberos=/usr/kerberos' '--with-ldap=shared' '--with-mysql=shared,/usr' '--with-pgsql=shared' '--with-snmp=shared,/usr' '--with-snmp=shared' '--enable-ucd-snmp-hack' '--with-unixODBC=shared' '--enable-memory-limit' '--enable-bcmath' '--enable-shmop' '--enable-versioning' '--enable-calendar' '--enable-dbx' '--enable-dio' '--enable-mcal' '--enable-mbstring' '--enable-mbstr-enc-trans' '--with-apxs=/usr/sbin/apxs'

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-07-11 10:28 UTC] sander@php.net
t('test') MUST be quoted because it's not a valid value (IIRC, only a-z, 0-9, - & _ are allowed.
Reopen this report if it still doesn't work when you quote the values.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 21:00:01 2026 UTC