A side note: I'm guessing that you have register globals on since $page isn't declared from the GET/POST/SESSION arrays. It may not matter in this particular case but, with reg globs on, anyone can submit any var with any value to a script.
That is particularly risky if you have undefined vars in scripts (and why it's essential to develop with E_ALL error reporting).
If you don't have any undefined vars, reg globs on doesn't pose any threat.