Fixes a potential cross-site scripting vulnerablity: quote attributes that need escaping in legacy browsers. (CVE-2016-9909, CVE-2016-9910)