From 5c5689734955ced9ca81690ad9c1b76b71a8712a Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Mon, 22 Oct 2012 01:19:06 +0400 Subject: [PATCH] properly escape article link/PTITLEs (refs #472) --- classes/feeds.php | 2 +- include/functions.php | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/classes/feeds.php b/classes/feeds.php index 31224d1db..5280502c4 100644 --- a/classes/feeds.php +++ b/classes/feeds.php @@ -503,7 +503,7 @@ class Feeds extends Handler_Protected { $reply['content'] .= ""; $reply['content'] .= "
" . - strip_tags($line['title']) . "
"; + htmlspecialchars(strip_tags($line['title'])) . ""; $reply['content'] .= ""; } - $title_escaped = db_escape_string($line['title']); + $title_escaped = htmlspecialchars($line['title']); $rv['content'] .= "
" . truncate_string(strip_tags($line['title']), 15) . "
"; @@ -3400,7 +3400,7 @@ $rv['content'] .= ""; } else {