#38349 [Opn->Bgs]: PHPSESSID is appended in HTML contents of text fields

From: Date: Sat, 05 Aug 2006 17:51:15 +0000
Subject: #38349 [Opn->Bgs]: PHPSESSID is appended in HTML contents of text fields
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-100399@lists.php.net to get a copy of this message
ID: 38349 Updated by: tony2001@php.net Reported By: matei dot tene at unidec dot ro -Status: Open +Status: Bogus Bug Type: Session related Operating System: Windows 2000 PHP Version: 4.4.3 New Comment: Thank you for taking the time to report a problem with PHP. Unfortunately you are not using a current version of PHP -- the problem might already be fixed. Please download a new PHP version from http://www.php.net/downloads.php If you are able to reproduce the bug with one of the latest versions of PHP, please change the PHP version on this bug report to the version you tested and change the status back to "Open". Again, thank you for your continued support of PHP. Previous Comments: ------------------------------------------------------------------------ [2006-08-05 17:45:20] matei dot tene at unidec dot ro Description: ------------ Well. I guess that many forum administrators that allow html in posts have this problem. I am using php 4.2.2, and i have a form who's contents can (and most frequently do) contain html tags like <a href="...">. This form is filled out in the administration portion of the site (which requires authentification and thus uses sessions). The problem is that, upon submission, PHP appends the PHPSESSID in the html tags contained in the body of the text fields, like: <form> <input type=text value="<a href=http://url>"> </form> becomes <form> <input type=text value="<a href=http://url?PHPSESSID=1234565756..>"> </form> Has this been fixed in later versions of PHP? ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=38349&edit=1

« previous php.bugs (#100399) next »