set_context('search');\r
\r
// Get input\r
- $tag = get_input('tag');\r
+ $tag = stripslashes(get_input('tag'));\r
\r
if (!empty($tag)) {\r
$title = sprintf(elgg_echo('groups:searchtitle'),$tag);\r
set_context('search');\r
\r
// Get input\r
- $tag = get_input('tag');\r
- $subtype = get_input('subtype');\r
- if (!$objecttype = get_input('object')) {\r
+ $tag = stripslashes(get_input('tag'));\r
+ $subtype = stripslashes(get_input('subtype'));\r
+ if (!$objecttype = stripslashes(get_input('object'))) {\r
$objecttype = "";\r
}\r
- if (!$md_type = get_input('tagtype')) {\r
+ if (!$md_type = stripslashes(get_input('tagtype'))) {\r
$md_type = ""; \r
}\r
- $owner_guid = get_input('owner_guid',0);\r
+ $owner_guid = (int)get_input('owner_guid',0);\r
if (substr_count($owner_guid,',')) {\r
$owner_guid_array = explode(",",$owner_guid);\r
} else {\r
*/\r
\r
// Load Elgg engine\r
- require_once(dirname(dirname(__FILE__)) . "/engine/start.php");\r
+ require_once(dirname(dirname(__FILE__)) . "/engine/start.php");
\r
// Set context\r
set_context('search');\r
\r
// Get input\r
- $tag = get_input('tag');\r
+ $tag = stripslashes(get_input('tag'));\r
\r
if (!empty($tag)) {\r
$title = sprintf(elgg_echo('users:searchtitle'),$tag);\r