[wp-svn] [5056] trunk: use clean_url() instead of
attribute_escape() when dealing with src/href to protect
against XSS.
m at wordpress.org
m at wordpress.org
Sat Mar 17 08:47:07 GMT 2007
An HTML attachment was scrubbed...
URL: http://comox.textdrive.com/pipermail/wp-svn/attachments/20070317/cd7b5b1b/attachment-0001.htm
More information about the wp-svn
mailing list