case FORMAT_HTML:
case FORMAT_WIKI:
$text = strip_tags($text, $ALLOWED_TAGS);
- $text = str_ireplace("javascript:", " ", $text); // Remove javascript: label
- $text = eregi_replace("([^a-z])language([[:space:]]*)=", " ", $text); // Remove javascript/VBScript
- $text = eregi_replace("([^a-z])on([a-z]+)([[:space:]]*)=", " ", $text); // Remove script events
+ $text = str_ireplace("javascript:", "xxx", $text); // Remove javascript: label
+ $text = eregi_replace("([^a-z])language([[:space:]]*)=", "xxx", $text); // Remove javascript/VBScript
+ $text = eregi_replace("([^a-z])on([a-z]+)([[:space:]]*)=", "xxx", $text); // Remove script events
return $text;
case FORMAT_PLAIN: