diff --git a/classes/feeds.php b/classes/feeds.php index 31224d1db..5280502c4 100644 --- a/classes/feeds.php +++ b/classes/feeds.php @@ -503,7 +503,7 @@ class Feeds extends Handler_Protected { $reply['content'] .= ""; $reply['content'] .= "
" . - strip_tags($line['title']) . "
"; + htmlspecialchars(strip_tags($line['title'])) . ""; $reply['content'] .= ""; } - $title_escaped = db_escape_string($line['title']); + $title_escaped = htmlspecialchars($line['title']); $rv['content'] .= "
" . truncate_string(strip_tags($line['title']), 15) . "
"; @@ -3400,7 +3400,7 @@ $rv['content'] .= "
" . + htmlspecialchars($line["link"]) . "\">" . $line["title"] . "$entry_author
"; } else {