diff --git a/guestbook/index.php b/guestbook/index.php index 8ca20d5..3af0e6e 100755 --- a/guestbook/index.php +++ b/guestbook/index.php @@ -28,9 +28,6 @@ prepare('SELECT COUNT(*) FROM Entries'); $count_query->execute(); diff --git a/guestbook/submit.php b/guestbook/submit.php index 9187223..8c38dca 100755 --- a/guestbook/submit.php +++ b/guestbook/submit.php @@ -17,16 +17,13 @@
You must provide both a name and message!'; } else { $db = new PDO("sqlite:/mnt/data1/webdata/floppydisk/guestbook.db"); $name = $_POST["name"]; - $msg = strip_tags($_POST["message"]); + $msg = htmlspecialchars($_POST["message"]); $showinfo = isset($_POST["showinfo"]) ? true : false; $showip = isset($_POST["showip"]) ? true : false; $ip = $_SERVER['REMOTE_ADDR'];