$reply['content'] .= "</div>";\r
\r
$reply['content'] .= "<div id=\"PTITLE-FULL-$id\" style=\"display : none\">" .\r
- strip_tags($line['title']) . "</div>";\r
+ htmlspecialchars(strip_tags($line['title'])) . "</div>";\r
\r
$reply['content'] .= "<span id=\"RTITLE-$id\"\r
onclick=\"return cdmClicked(event, $id);\"\r
</head><body>";
}
- $title_escaped = db_escape_string($line['title']);
+ $title_escaped = htmlspecialchars($line['title']);
$rv['content'] .= "<div id=\"PTITLE-$id\" style=\"display : none\">" .
truncate_string(strip_tags($line['title']), 15) . "</div>";
$rv['content'] .= "<div class='postTitle'><a target='_blank'
title=\"".htmlspecialchars($line['title'])."\"
href=\"" .
- $line["link"] . "\">" .
+ htmlspecialchars($line["link"]) . "\">" .
$line["title"] .
"<span class='author'>$entry_author</span></a></div>";
} else {