$title = serendipity_db_query("SELECT title FROM {$serendipity['dbPrefix']}entries WHERE id=$id AND isdraft = 'false' " . (!serendipity_db_bool($serendipity['showFutureEntries']) ? " AND timestamp <= " . time() : ''), true);
if (is_array($title)) {
- $serendipity['head_title'] = $title[0];
- $serendipity['head_subtitle'] = $serendipity['blogTitle'];
+ $serendipity['head_title'] = htmlspecialchars($title[0]);
+ $serendipity['head_subtitle'] = htmlspecialchars($serendipity['blogTitle']);
}
ob_start();