Make WordPress Core


Ignore:
Timestamp:
05/04/2009 05:54:08 PM (17 years ago)
Author:
ryan
Message:

Attr escaping

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/post-template.php

    r11112 r11173  
    708708            $output .= "\t<option value=\"-1\">$show_option_no_change</option>";
    709709        if ( $show_option_none )
    710             $output .= "\t<option value=\"$option_none_value\">$show_option_none</option>\n";
     710            $output .= "\t<option value=\"" . attr($option_none_value) . "\">$show_option_none</option>\n";
    711711        $output .= walk_page_dropdown_tree($pages, $depth, $r);
    712712        $output .= "</select>\n";
     
    11351135    $output = '<form action="' . get_option('siteurl') . '/wp-pass.php" method="post">
    11361136    <p>' . __("This post is password protected. To view it please enter your password below:") . '</p>
    1137     <p><label for="' . $label . '">' . __("Password:") . ' <input name="post_password" id="' . $label . '" type="password" size="20" /></label> <input type="submit" name="Submit" value="' . __("Submit") . '" /></p>
     1137    <p><label for="' . $label . '">' . __("Password:") . ' <input name="post_password" id="' . $label . '" type="password" size="20" /></label> <input type="submit" name="Submit" value="' . _a("Submit") . '" /></p>
    11381138    </form>
    11391139    ';
     
    13171317<div class="tablenav">
    13181318    <div class="alignleft">
    1319         <input type="submit" class="button-secondary" value="<?php _e( 'Compare Revisions' ); ?>" />
     1319        <input type="submit" class="button-secondary" value="<?php _ea( 'Compare Revisions' ); ?>" />
    13201320        <input type="hidden" name="action" value="diff" />
    13211321    </div>
Note: See TracChangeset for help on using the changeset viewer.