aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--phpBB/viewforum.php4
-rw-r--r--phpBB/viewtopic.php4
2 files changed, 4 insertions, 4 deletions
diff --git a/phpBB/viewforum.php b/phpBB/viewforum.php
index 8634a4a7a3..6361e86c9b 100644
--- a/phpBB/viewforum.php
+++ b/phpBB/viewforum.php
@@ -31,8 +31,8 @@ $start = (isset($_GET['start'])) ? max(intval($_GET['start']), 0) : 0;
$mark_read = (!empty($_GET['mark'])) ? $_GET['mark'] : '';
$sort_days = (!empty($_REQUEST['st'])) ? max(intval($_REQUEST['st']), 0) : 0;
-$sort_key = (!empty($_REQUEST['sk'])) ? $_REQUEST['sk'] : 't';
-$sort_dir = (!empty($_REQUEST['sd'])) ? $_REQUEST['sd'] : 'd';
+$sort_key = (!empty($_REQUEST['sk'])) ? htmlspecialchars($_REQUEST['sk']) : 't';
+$sort_dir = (!empty($_REQUEST['sd'])) ? htmlspecialchars($_REQUEST['sd']) : 'd';
// Start session
diff --git a/phpBB/viewtopic.php b/phpBB/viewtopic.php
index f1b13702ed..7e3539d469 100644
--- a/phpBB/viewtopic.php
+++ b/phpBB/viewtopic.php
@@ -37,8 +37,8 @@ $start = (isset($_GET['start'])) ? max(intval($_GET['start']), 0) : 0;
// if someone wishes to screw their view up by entering unknown data
// good luck to them :D
$sort_days = (!empty($_REQUEST['st'])) ? max(intval($_REQUEST['st']), 0) : 0;
-$sort_key = (!empty($_REQUEST['sk'])) ? $_REQUEST['sk'] : 't';
-$sort_dir = (!empty($_REQUEST['sd'])) ? $_REQUEST['sd'] : 'a';
+$sort_key = (!empty($_REQUEST['sk'])) ? htmlspecialchars($_REQUEST['sk']) : 't';
+$sort_dir = (!empty($_REQUEST['sd'])) ? htmlspecialchars($_REQUEST['sd']) : 'a';
// Do we have a topic or post id?