The user_logout.php script is used by the single-login hack. The error you are getting seems to be complaining about the `$_SESSION` variable. That should be a PHP special global, so I do not know why it would not be setup correctly. However, you can avoid the error by changing line 22 from:
`$candidate = array_unique(Array_merge(array_keys($_COOKIE), $_SESSION));`
to:
`$candidate = array_keys($_COOKIE);`
This will not be compatible with the `album sessions` option, though.