aboutsummaryrefslogtreecommitdiff
path: root/mod/search/views/default/search/search_box.php
diff options
context:
space:
mode:
Diffstat (limited to 'mod/search/views/default/search/search_box.php')
-rw-r--r--mod/search/views/default/search/search_box.php7
1 files changed, 7 insertions, 0 deletions
diff --git a/mod/search/views/default/search/search_box.php b/mod/search/views/default/search/search_box.php
index 7561a3767..ff5910937 100644
--- a/mod/search/views/default/search/search_box.php
+++ b/mod/search/views/default/search/search_box.php
@@ -15,8 +15,15 @@ if (array_key_exists('value', $vars)) {
$value = elgg_echo('search');
}
+// @todo - why the strip slashes?
$value = stripslashes($value);
+// @todo - create function for sanitization of strings for display in 1.8
+// encode <,>,&, quotes and characters above 127
+$display_query = mb_convert_encoding($value, 'HTML-ENTITIES', 'UTF-8');
+$display_query = htmlspecialchars($display_query, ENT_QUOTES, 'UTF-8', false);
+
+
?>
<form class="elgg-search" action="<?php echo elgg_get_site_url(); ?>search" method="get">