View Single Post
Old Feb 26th, 2008, 7:56 AM   #3
Ooble
I eat cake for breakfast.
 
Ooble's Avatar
 
Join Date: Jul 2004
Location: In my box.
Posts: 4,434
Rep Power: 9 Ooble is on a distinguished road
Re: Sending Forms with GET variables from other forms

Little tip: never just chuck out unescaped user input. Try this:
<input type="hidden" name="action" value="<?php echo htmlspecialchars($_GET['action']) ?>" />
__________________
Me :: You :: Them
Ooble is offline   Reply With Quote