Make WordPress Core


Ignore:
Timestamp:
03/17/2007 09:04:56 AM (18 years ago)
Author:
markjaquith
Message:

use clean_url() instead of attribute_escape() when dealing with src/href to protect against XSS. props xknown. fixes #3986 for 2.0.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/2.0/wp-includes/template-functions-links.php

    r5047 r5058  
    459459
    460460function next_posts($max_page = 0) {
    461     echo attribute_escape(get_next_posts_page_link($max_page));
     461    echo clean_url(get_next_posts_page_link($max_page));
    462462}
    463463
     
    496496
    497497function previous_posts() {
    498     echo attribute_escape(get_previous_posts_page_link());
     498    echo clean_url(get_previous_posts_page_link());
    499499}
    500500
Note: See TracChangeset for help on using the changeset viewer.