diff --git a/include/setup.php b/include/setup.php index 879dc340..a4ac77d6 100644 --- a/include/setup.php +++ b/include/setup.php @@ -585,6 +585,7 @@ function createRevisionSelectionForm() { $vars['revision_form'] = '
'.$hidden; if ($rev === null) $rev = (int)@$_REQUEST['rev']; + $rev = escape($rev); $vars['revision_input'] = ''; $vars['revision_submit'] = ''; $vars['revision_endform'] = '
'; @@ -611,6 +612,7 @@ function createSearchSelectionForm() { $vars['search'] = true; $vars['search_form'] = '';