diff --git a/htdocs/admin/tools/export.php b/htdocs/admin/tools/export.php index ee5edc7ddb9..2f6c6ce2279 100644 --- a/htdocs/admin/tools/export.php +++ b/htdocs/admin/tools/export.php @@ -35,7 +35,7 @@ $file=GETPOST('filename_template','alpha'); $sortfield = GETPOST('sortfield','alpha'); $sortorder = GETPOST('sortorder','alpha'); -$page = GETPOST("page"); +$page = GETPOST("page",'int'); if (! $sortorder) $sortorder="DESC"; if (! $sortfield) $sortfield="date"; if ($page < 0) { $page = 0; } diff --git a/htdocs/comm/action/index.php b/htdocs/comm/action/index.php index abd61760e75..1de6c0678d8 100644 --- a/htdocs/comm/action/index.php +++ b/htdocs/comm/action/index.php @@ -42,8 +42,8 @@ $filterd = GETPOST("userdone","int",3)?GETPOST("userdone","int",3):GETPOST("filt $showbirthday = empty($conf->use_javascript_ajax)?GETPOST("showbirthday","int"):1; -$sortfield = GETPOST("sortfield"); -$sortorder = GETPOST("sortorder"); +$sortfield = GETPOST("sortfield",'alpha'); +$sortorder = GETPOST("sortorder",'alpha'); $page = GETPOST("page","int"); if ($page == -1) { $page = 0; } $limit = $conf->liste_limit; diff --git a/htdocs/compta/paiement.php b/htdocs/compta/paiement.php index ed6e0c7f0aa..0ebe94d2d8a 100644 --- a/htdocs/compta/paiement.php +++ b/htdocs/compta/paiement.php @@ -42,9 +42,9 @@ $socname = GETPOST('socname'); $accountid = GETPOST('accountid'); $paymentnum = GETPOST('num_paiement'); -$sortfield = GETPOST('sortfield'); -$sortorder = GETPOST('sortorder'); -$page = GETPOST('page'); +$sortfield = GETPOST('sortfield','alpha'); +$sortorder = GETPOST('sortorder','alpha'); +$page = GETPOST('page','int'); $amounts=array(); $amountsresttopay=array(); diff --git a/htdocs/contrat/services.php b/htdocs/contrat/services.php index 97ad5eae634..9c7c76ed0d0 100644 --- a/htdocs/contrat/services.php +++ b/htdocs/contrat/services.php @@ -35,7 +35,7 @@ $langs->load("companies"); $mode = GETPOST("mode"); $sortfield = GETPOST("sortfield",'alpha'); $sortorder = GETPOST("sortorder",'alpha'); -$page = GETPOST("page"); +$page = GETPOST("page",'int'); if ($page == -1) { $page = 0 ; } $limit = $conf->liste_limit; $offset = $limit * $page ; diff --git a/htdocs/fourn/commande/liste.php b/htdocs/fourn/commande/liste.php index b9960a1e499..5bfbf4cff62 100644 --- a/htdocs/fourn/commande/liste.php +++ b/htdocs/fourn/commande/liste.php @@ -37,8 +37,8 @@ $sall=GETPOST('search_all'); $page = GETPOST('page','int'); $socid = GETPOST('socid','int'); -$sortorder = GETPOST('sortorder'); -$sortfield = GETPOST('sortfield'); +$sortorder = GETPOST('sortorder','alpha'); +$sortfield = GETPOST('sortfield','alpha'); // Security check $orderid = GETPOST('orderid'); diff --git a/htdocs/fourn/facture/index.php b/htdocs/fourn/facture/index.php index c141d627715..d7cb3dd3d8c 100644 --- a/htdocs/fourn/facture/index.php +++ b/htdocs/fourn/facture/index.php @@ -47,9 +47,9 @@ if ($user->societe_id > 0) $mode=GETPOST("mode"); $modesearch=GETPOST("mode_search"); -$page=GETPOST("page"); -$sortorder = GETPOST("sortorder"); -$sortfield = GETPOST("sortfield"); +$page=GETPOST("page",'int'); +$sortorder = GETPOST("sortorder",'alpha'); +$sortfield = GETPOST("sortfield",'alpha'); if ($page == -1) { $page = 0 ; } $limit = $conf->liste_limit; diff --git a/htdocs/fourn/liste.php b/htdocs/fourn/liste.php index 5c99d0d0bc6..7589e021e6e 100644 --- a/htdocs/fourn/liste.php +++ b/htdocs/fourn/liste.php @@ -45,9 +45,9 @@ $socid = GETPOST('socid','int'); if ($user->societe_id) $socid=$user->societe_id; $result = restrictedArea($user,'societe',$socid,''); -$page = GETPOST('page'); -$sortorder = GETPOST('sortorder'); -$sortfield = GETPOST('sortfield'); +$page = GETPOST('page','int'); +$sortorder = GETPOST('sortorder','alpha'); +$sortfield = GETPOST('sortfield','alpha'); if ($page == -1) { $page = 0 ; } $offset = $conf->liste_limit * $page ; $pageprev = $page - 1; diff --git a/htdocs/holiday/index.php b/htdocs/holiday/index.php index 8ca966b451c..4a10e6712d0 100644 --- a/htdocs/holiday/index.php +++ b/htdocs/holiday/index.php @@ -33,9 +33,9 @@ require_once DOL_DOCUMENT_ROOT.'/holiday/common.inc.php'; // Protection if external user if ($user->societe_id > 0) accessforbidden(); -$sortfield = GETPOST("sortfield"); -$sortorder = GETPOST("sortorder"); -$page = GETPOST("page"); +$sortfield = GETPOST("sortfield",'alpha'); +$sortorder = GETPOST("sortorder",'alpha'); +$page = GETPOST("page",'int'); $page = is_numeric($page) ? $page : 0; $page = $page == -1 ? 0 : $page; diff --git a/htdocs/product/stock/fiche.php b/htdocs/product/stock/fiche.php index f4807cfb822..6e7f1eafd98 100644 --- a/htdocs/product/stock/fiche.php +++ b/htdocs/product/stock/fiche.php @@ -37,8 +37,8 @@ $langs->load("companies"); $action=GETPOST('action'); -$sortfield = GETPOST("sortfield"); -$sortorder = GETPOST("sortorder"); +$sortfield = GETPOST("sortfield",'alpha'); +$sortorder = GETPOST("sortorder",'alpha'); if (! $sortfield) $sortfield="p.ref"; if (! $sortorder) $sortorder="DESC"; @@ -536,7 +536,7 @@ else print '

 '; print '
'; - + print ''; } diff --git a/htdocs/product/stock/mouvement.php b/htdocs/product/stock/mouvement.php index b9fa376ff67..7694e355031 100644 --- a/htdocs/product/stock/mouvement.php +++ b/htdocs/product/stock/mouvement.php @@ -48,9 +48,9 @@ $search_movement = isset($_REQUEST["search_movement"])?$_REQUEST["search_movemen $search_product = isset($_REQUEST["search_product"])?$_REQUEST["search_product"]:''; $search_warehouse = isset($_REQUEST["search_warehouse"])?$_REQUEST["search_warehouse"]:''; $search_user = isset($_REQUEST["search_user"])?$_REQUEST["search_user"]:''; -$page = GETPOST("page"); -$sortfield = GETPOST("sortfield"); -$sortorder = GETPOST("sortorder"); +$page = GETPOST("page",'int'); +$sortfield = GETPOST("sortfield",'alpha'); +$sortorder = GETPOST("sortorder",'alpha'); if ($page < 0) $page = 0; $offset = $conf->liste_limit * $page; diff --git a/htdocs/societe/societe.php b/htdocs/societe/societe.php index ab8bbef42c5..827b646bf13 100644 --- a/htdocs/societe/societe.php +++ b/htdocs/societe/societe.php @@ -51,9 +51,9 @@ $search_categ=trim(GETPOST("search_categ")); $mode=GETPOST("mode"); $modesearch=GETPOST("mode_search"); -$sortfield=GETPOST("sortfield"); -$sortorder=GETPOST("sortorder"); -$page=GETPOST("page"); +$sortfield=GETPOST("sortfield",'alpha'); +$sortorder=GETPOST("sortorder",'alpha'); +$page=GETPOST("page",'int'); if (! $sortorder) $sortorder="ASC"; if (! $sortfield) $sortfield="s.nom"; if ($page == -1) { $page = 0 ; }