Bug #14080: The doubledoublequote strikes again

From: Date: Fri, 16 Nov 2001 10:56:16 +0000
Subject: Bug #14080: The doubledoublequote strikes again
Groups: php.dev 
Request: Send a blank email to php-dev+get-70629@lists.php.net to get a copy of this message
From:             fischer@ms-net.de
Operating system: FreeBSD 4.4
PHP version:      4.0.6
PHP Bug Type:     Session related
Bug description:  The doubledoublequote strikes again

I came across the bug described in Bug-ID #8311 with 4.03pl1
on our old Server, so I transfered it to the new Server running 4.0.6 and
the behaviour is nearly the same.
This:
<?php
session_start();
$somevar = "<a href=\"javascript:;\"
onClick=window.open(\"/hardware/somevar.php?hinfoid=".$somevar_id."\",\"chgti\",\"location=0,directories=0,status=0,menubar=0,scrollbars=0,toolbar=0,width=450,height=470\");>Badlink</a>";
echo $somevar;
?>

produces this:
<a href="javascript:;"
onClick="window.open(""/hardware/somevar.php?hinfoid=","chgti","location=0,directories=0,status=0,menubar=0,scrollbars=0,toolbar=0,width=450,height=470");>Badlink</a>

Without the session, the Output is normal, both with 4.0.3pl1 and 4.06.
The only difference is that 4.0.6 does a few less quotes than 4.0.3pl1.

Trans-SID is enabled, PHP is running as an Apache-Module



-- 
Edit bug report at: http://bugs.php.net/?id=14080&edit=1



Thread (5 messages)

« previous php.dev (#70629) next »