Make WordPress Core


Ignore:
Timestamp:
04/28/2009 06:37:51 AM (16 years ago)
Author:
ryan
Message:

attr escaping. see #9650

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/update-core.php

    r11109 r11110  
    4141    wp_nonce_field('upgrade-core');
    4242    echo '<p>';
    43     echo '<input id="upgrade" class="button" type="submit" value="' . $submit . '" name="upgrade" />&nbsp;';
    44     echo '<input name="version" value="'.$update->current.'" type="hidden"/>';
    45     echo '<input name="locale" value="'.$update->locale.'" type="hidden"/>';
    46     echo '<a href="' . $update->package . '" class="button">' . $download . '</a>&nbsp;';
     43    echo '<input id="upgrade" class="button" type="submit" value="' . attr($submit) . '" name="upgrade" />&nbsp;';
     44    echo '<input name="version" value="'. attr($update->current) .'" type="hidden"/>';
     45    echo '<input name="locale" value="'. attr($update->locale) .'" type="hidden"/>';
     46    echo '<a href="' . clean_url($update->package) . '" class="button">' . $download . '</a>&nbsp;';
    4747    if ( 'en_US' != $update->locale )
    4848        if ( !isset( $update->dismissed ) || !$update->dismissed )
    49             echo '<input id="dismiss" class="button" type="submit" value="' . attr(__('Hide this update')) . '" name="dismiss" />';
     49            echo '<input id="dismiss" class="button" type="submit" value="' . _a('Hide this update') . '" name="dismiss" />';
    5050        else
    51             echo '<input id="undismiss" class="button" type="submit" value="' . attr(__('Bring back this update')) . '" name="undismiss" />';
     51            echo '<input id="undismiss" class="button" type="submit" value="' . _a('Bring back this update') . '" name="undismiss" />';
    5252    echo '</p>';
    5353    echo '</form>';
Note: See TracChangeset for help on using the changeset viewer.