Make WordPress Core


Ignore:
Timestamp:
07/28/2004 11:09:33 PM (21 years ago)
Author:
rboren
Message:

Run htmlspecialchars on title attribute text in get_archives_link(). Bug 0000162.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-includes/template-functions-general.php

    r1492 r1497  
    195195function get_archives_link($url, $text, $format = 'html', $before = '', $after = '') {
    196196    $text = wptexturize($text);
     197    $title_text = htmlspecialchars($text);
     198
    197199    if ('link' == $format) {
    198         return "\t<link rel='archives' title='$text' href='$url' />\n";
     200        return "\t<link rel='archives' title='$title_text' href='$url' />\n";
    199201    } elseif ('option' == $format) {
    200202        return "\t<option value='$url'>$text</option>\n";
    201203    } elseif ('html' == $format) {
    202         return "\t<li>$before<a href='$url' title='$text'>$text</a>$after</li>\n";
     204        return "\t<li>$before<a href='$url' title='$title_text'>$text</a>$after</li>\n";
    203205    } else { // custom
    204         return "\t$before<a href='$url' title='$text'>$text</a>$after\n";
     206        return "\t$before<a href='$url' title='$title_text'>$text</a>$after\n";
    205207    }
    206208}
Note: See TracChangeset for help on using the changeset viewer.