Don't entity encode the URL we give to JavaScript.
[pr0n] / close.png
close.png