Make WordPress Core


Ignore:
Timestamp:
03/17/2007 08:47:29 AM (19 years ago)
Author:
markjaquith
Message:

use clean_url() instead of attribute_escape() when dealing with src/href to protect against XSS. props xknown. fixes #3986 for 2.1.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/2.1/wp-admin/edit-form-advanced.php

    r4760 r5057  
    169169<input name="referredby" type="hidden" id="referredby" value="<?php
    170170if ( !empty($_REQUEST['popupurl']) )
    171     echo attribute_escape(stripslashes($_REQUEST['popupurl']));
     171    echo clean_url(stripslashes($_REQUEST['popupurl']));
    172172else if ( url_to_postid(wp_get_referer()) == $post_ID )
    173173    echo 'redo';
    174174else
    175     echo attribute_escape(stripslashes(wp_get_referer()));
     175    echo clean_url(stripslashes(wp_get_referer()));
    176176?>" /></p>
    177177
Note: See TracChangeset for help on using the changeset viewer.