Make WordPress Core


Ignore:
Timestamp:
04/28/2009 06:37:51 AM (17 years ago)
Author:
ryan
Message:

attr escaping. see #9650

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/sidebar.php

    r8834 r11110  
    8989<div>
    9090<input type="hidden" name="action" value="post" />
    91 <input type="hidden" name="user_ID" value="<?php echo $user_ID ?>" />
     91<input type="hidden" name="user_ID" value="<?php echo attr($user_ID) ?>" />
    9292<input type="hidden" name="mode" value="sidebar" />
    93 <input type="hidden" name="ping_status" value="<?php echo $post->ping_status; ?>" />
    94 <input type="hidden" name="comment_status" value="<?php echo $post->comment_status; ?>" />
     93<input type="hidden" name="ping_status" value="<?php echo attr($post->ping_status); ?>" />
     94<input type="hidden" name="comment_status" value="<?php echo attr($post->comment_status); ?>" />
    9595<?php wp_nonce_field('add-post');
    9696
     
    117117
    118118<p>
    119 <input name="saveasdraft" type="submit" id="saveasdraft" tabindex="9" accesskey="s" class="button" value="<?php _e('Save as Draft'); ?>" />
     119<input name="saveasdraft" type="submit" id="saveasdraft" tabindex="9" accesskey="s" class="button" value="<?php _ea('Save as Draft'); ?>" />
    120120<?php if ( current_user_can('publish_posts') ) : ?>
    121 <input name="publish" type="submit" id="publish" tabindex="6" accesskey="p" value="<?php _e('Publish') ?>" class="button button-highlighted" />
     121<input name="publish" type="submit" id="publish" tabindex="6" accesskey="p" value="<?php _ea('Publish') ?>" class="button button-highlighted" />
    122122<?php endif; ?>
    123123</p>
Note: See TracChangeset for help on using the changeset viewer.