$arr['asf'] = "".$settings->install_url."/viewer.php?reserve_id=".$r->id;
$arr['title'] = htmlspecialchars($r->title,ENT_QUOTES);
$arr['description'] = htmlspecialchars($r->description,ENT_QUOTES);
- $arr['thumb'] = "<img src=\"".$settings->install_url.$settings->thumbs."/".$r->path.".jpg\" />";
+ $arr['thumb'] = "<img src=\"".$settings->install_url.$settings->thumbs."/".htmlentities($r->path, ENT_QUOTES,"UTF-8").".jpg\" />";
$arr['cat'] = $cat->name_en;
$arr['mode'] = $RECORD_MODE[$r->mode]['name'];