Full Version: xss attack
when writing " onmouseover=prompt(986271) bad=" in a form text element and the form does not validate,
you get a prompt.

How can I prevent this?

Output the value of the form element either like this:

<input type="text" name="email" value="<?php echo html_escape($email); ?>" />

Or like this

<input type="text" name="email" value="<?php echo set_value('email'); ?>" />

Either method will escape your data for output to the screen.