Be sure that the text is escaped
authorAlexandre Emsenhuber <ialex@users.mediawiki.org>
Sun, 13 Apr 2008 20:03:09 +0000 (20:03 +0000)
committerAlexandre Emsenhuber <ialex@users.mediawiki.org>
Sun, 13 Apr 2008 20:03:09 +0000 (20:03 +0000)
includes/LogPage.php

index fa21f02..0dcb1f2 100644 (file)
@@ -158,7 +158,7 @@ class LogPage {
 
                                        switch( $type ) {
                                                case 'move':
-                                                       $titleLink = $skin->makeLinkObj( $title, $title->getPrefixedText(), 'redirect=no' );
+                                                       $titleLink = $skin->makeLinkObj( $title, htmlspecialchars( $title->getPrefixedText() ), 'redirect=no' );
                                                        $params[0] = $skin->makeLinkObj( Title::newFromText( $params[0] ), htmlspecialchars( $params[0] ) );
                                                        break;
                                                case 'block':