Properly escape the search term here.
authorRobert Stojnić <rainman@users.mediawiki.org>
Fri, 24 Jul 2009 11:12:09 +0000 (11:12 +0000)
committerRobert Stojnić <rainman@users.mediawiki.org>
Fri, 24 Jul 2009 11:12:09 +0000 (11:12 +0000)
includes/specials/SpecialSearch.php

index 9b037c6..8acb8df 100644 (file)
@@ -884,7 +884,7 @@ class SpecialSearch {
                if ( $resultsShown > 0 ) {
                        if ( $totalNum > 0 ){
                                $top = wfMsgExt('showingresultsheader', array( 'parseinline' ),
-                                       $this->offset+1, $this->offset+$resultsShown, $totalNum, $term, $resultsShown );
+                                       $this->offset+1, $this->offset+$resultsShown, $totalNum, wfEscapeWikiText($term), $resultsShown );
                        } elseif ( $resultsShown >= $this->limit ) {
                                $top = wfShowingResults( $this->offset, $this->limit );
                        } else {