Changeset 11204 for trunk/wp-includes/functions.php
- Timestamp:
- 05/05/2009 07:43:53 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/wp-includes/functions.php
r11190 r11204 394 394 */ 395 395 function form_option( $option ) { 396 echo attr(get_option( $option ) );396 echo esc_attr(get_option( $option ) ); 397 397 } 398 398 … … 1744 1744 */ 1745 1745 function wp_nonce_field( $action = -1, $name = "_wpnonce", $referer = true , $echo = true ) { 1746 $name = attr( $name );1746 $name = esc_attr( $name ); 1747 1747 $nonce_field = '<input type="hidden" id="' . $name . '" name="' . $name . '" value="' . wp_create_nonce( $action ) . '" />'; 1748 1748 if ( $echo ) … … 1769 1769 */ 1770 1770 function wp_referer_field( $echo = true) { 1771 $ref = attr( $_SERVER['REQUEST_URI'] );1771 $ref = esc_attr( $_SERVER['REQUEST_URI'] ); 1772 1772 $referer_field = '<input type="hidden" name="_wp_http_referer" value="'. $ref . '" />'; 1773 1773 … … 1795 1795 $jump_back_to = ( 'previous' == $jump_back_to ) ? wp_get_referer() : $_SERVER['REQUEST_URI']; 1796 1796 $ref = ( wp_get_original_referer() ) ? wp_get_original_referer() : $jump_back_to; 1797 $orig_referer_field = '<input type="hidden" name="_wp_original_http_referer" value="' . attr( stripslashes( $ref ) ) . '" />';1797 $orig_referer_field = '<input type="hidden" name="_wp_original_http_referer" value="' . esc_attr( stripslashes( $ref ) ) . '" />'; 1798 1798 if ( $echo ) 1799 1799 echo $orig_referer_field;
Note: See TracChangeset
for help on using the changeset viewer.