--- common.inc 2009-10-30 13:25:59.000000000 +0200 +++ common.inc 2010-02-05 14:27:37.000000000 +0200 @@ -2403,8 +2403,8 @@ function drupal_to_js($var) { return $var; case 'resource': case 'string': - return '"'. str_replace(array("\r", "\n", "<", ">", "&"), - array('\r', '\n', '\x3c', '\x3e', '\x26'), + return '"'. str_replace(array("\r", "\n", "<", ">", "&", "\'"), + array('\r', '\n', '\u003c', '\u003e', '\u0026', "'"), addslashes($var)) .'"'; case 'array': // Arrays in JSON can't be associative. If the array is empty or if it