<nobr><select name="_fo_searchkey">
{output_select_options(\@search_key_order,$search||'')}
</select>
-<input type="text" name="_fo_searchvalue" value ="{$search_value||''}">
+<input type="text" name="_fo_searchvalue" value ="{html_escape($search_value||'')}">
<!-- {$value_index} -->
</nobr>