Make WordPress Core


Ignore:
Timestamp:
12/21/2006 10:10:04 AM (19 years ago)
Author:
markjaquith
Message:

new function for escaping within attributes: attribute_escape()

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/users.php

    r4583 r4656  
    1313
    1414if ( empty($_POST) ) {
    15     $referer = '<input type="hidden" name="wp_http_referer" value="'. wp_specialchars(stripslashes($_SERVER['REQUEST_URI'])) . '" />';
     15    $referer = '<input type="hidden" name="wp_http_referer" value="'. attribute_escape(stripslashes($_SERVER['REQUEST_URI'])) . '" />';
    1616} elseif ( isset($_POST['wp_http_referer']) ) {
    1717    $redirect = remove_query_arg(array('wp_http_referer', 'updated', 'delete_count'), stripslashes($_POST['wp_http_referer']));
    18     $referer = '<input type="hidden" name="wp_http_referer" value="' . wp_specialchars($redirect) . '" />';
     18    $referer = '<input type="hidden" name="wp_http_referer" value="' . attribute_escape($redirect) . '" />';
    1919} else {
    2020    $redirect = 'users.php';
     
    339339
    340340    <form action="" method="get" name="search" id="search">
    341         <p><input type="text" name="usersearch" id="usersearch" value="<?php echo wp_specialchars($wp_user_search->search_term, 1); ?>" /> <input type="submit" value="<?php _e('Search     users &raquo;'); ?>" class="button" /></p>
     341        <p><input type="text" name="usersearch" id="usersearch" value="<?php echo attribute_escape($wp_user_search->search_term); ?>" /> <input type="submit" value="<?php _e('Search   users &raquo;'); ?>" class="button" /></p>
    342342    </form>
    343343
     
    430430        foreach ( array('user_login' => 'user_login', 'first_name' => 'user_firstname', 'last_name' => 'user_lastname', 'email' => 'user_email', 'url' => 'user_uri', 'role' => 'user_role') as $formpost => $var ) {
    431431            $var = 'new_' . $var;
    432             $$var = wp_specialchars(stripslashes($_POST[$formpost]));
     432            $$var = attribute_escape(stripslashes($_POST[$formpost]));
    433433        }
    434434        unset($name);
Note: See TracChangeset for help on using the changeset viewer.