Changeset 5057 for branches/2.1/wp-admin/admin-functions.php
- Timestamp:
- 03/17/2007 08:47:29 AM (18 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/2.1/wp-admin/admin-functions.php
r5007 r5057 359 359 $text = wp_specialchars( stripslashes( urldecode( $_REQUEST['text'] ) ) ); 360 360 $text = funky_javascript_fix( $text); 361 $popupurl = attribute_escape($_REQUEST['popupurl']);361 $popupurl = clean_url($_REQUEST['popupurl']); 362 362 $post_content = '<a href="'.$popupurl.'">'.$post_title.'</a>'."\n$text"; 363 363 } … … 418 418 $user->user_login = attribute_escape($user->user_login); 419 419 $user->user_email = attribute_escape($user->user_email); 420 $user->user_url = attribute_escape($user->user_url);420 $user->user_url = clean_url($user->user_url); 421 421 $user->first_name = attribute_escape($user->first_name); 422 422 $user->last_name = attribute_escape($user->last_name); … … 563 563 $link = get_link( $link_id ); 564 564 565 $link->link_url = attribute_escape($link->link_url);565 $link->link_url = clean_url($link->link_url); 566 566 $link->link_name = attribute_escape($link->link_name); 567 567 $link->link_image = attribute_escape($link->link_image); 568 568 $link->link_description = attribute_escape($link->link_description); 569 $link->link_rss = attribute_escape($link->link_rss);569 $link->link_rss = clean_url($link->link_rss); 570 570 $link->link_rel = attribute_escape($link->link_rel); 571 571 $link->link_notes = wp_specialchars($link->link_notes); … … 577 577 function get_default_link_to_edit() { 578 578 if ( isset( $_GET['linkurl'] ) ) 579 $link->link_url = attribute_escape( $_GET['linkurl']);579 $link->link_url = clean_url( $_GET['linkurl']); 580 580 else 581 581 $link->link_url = ''; … … 868 868 $r .= "</td>\n\t\t<td>"; 869 869 if ( current_user_can( 'edit_user', $user_object->ID ) ) { 870 $edit_link = attribute_escape( add_query_arg( 'wp_http_referer', urlencode( stripslashes( $_SERVER['REQUEST_URI'] ) ), "user-edit.php?user_id=$user_object->ID" ));870 $edit_link = clean_url( add_query_arg( 'wp_http_referer', urlencode( stripslashes( $_SERVER['REQUEST_URI'] ) ), "user-edit.php?user_id=$user_object->ID" )); 871 871 $r .= "<a href='$edit_link' class='edit'>".__( 'Edit' )."</a>"; 872 872 }
Note: See TracChangeset
for help on using the changeset viewer.