Make WordPress Core


Ignore:
Timestamp:
12/21/2006 10:10:04 AM (19 years ago)
Author:
markjaquith
Message:

new function for escaping within attributes: attribute_escape()

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/link-manager.php

    r4617 r4656  
    117117<input type="hidden" name="link_id" value="" />
    118118<input type="hidden" name="action" value="" />
    119 <input type="hidden" name="order_by" value="<?php echo wp_specialchars($order_by, 1); ?>" />
     119<input type="hidden" name="order_by" value="<?php echo attribute_escape($order_by); ?>" />
    120120<input type="hidden" name="cat_id" value="<?php echo (int) $cat_id ?>" />
    121121<table class="widefat">
     
    131131<?php
    132132    foreach ($links as $link) {
    133         $link->link_name = wp_specialchars($link->link_name);
     133        $link->link_name = attribute_escape($link->link_name);
    134134        $link->link_description = wp_specialchars($link->link_description);
    135         $link->link_url = wp_specialchars($link->link_url);
     135        $link->link_url = attribute_escape($link->link_url);
    136136        $link->link_category = wp_get_link_cats($link->link_id);
    137137        $short_url = str_replace('http://', '', $link->link_url);
Note: See TracChangeset for help on using the changeset viewer.