Ticket #3988: admin-header.diff

File admin-header.diff, 662 bytes (added by xknown, 5 years ago)

escape pagenow value

  • admin-header.php

     
    22@header('Content-type: ' . get_option('html_type') . '; charset=' . get_option('blog_charset')); 
    33if (!isset($_GET["page"])) require_once('admin.php'); 
    44if ( $editing ) { 
    5         wp_enqueue_script( array("dbx-admin-key?pagenow=$pagenow",'admin-custom-fields') ); 
     5        wp_enqueue_script( array('dbx-admin-key?pagenow=' . attribute_escape($pagenow),'admin-custom-fields') ); 
    66        if ( current_user_can('manage_categories') ) 
    77                wp_enqueue_script( 'ajaxcat' ); 
    88        if ( user_can_richedit() )