Mpff, you should start by minding XSS attacks on PHP_SELF, and no echoing it
as raw ... :
http://blog.phpdoc.info/archives/13-XSS-Woes.html

Reply via email to