Menu

#25 $url is not escaped in RSS head

open
nobody
None
5
2009-07-13
2009-07-13
Anonymous
No

Because $url is escaped after the head chunk is processed, the <link> field in the RSS header can contain illegal characters (e.g. tilde).

Discussion


Log in to post a comment.