foreach (@_field_names) { $_value = $_query->param($_); # convert special chars to html codes $_value =~ s/\x91/‘/g; # smart quotes $_value =~ s/\x92/’/g; $_value =~ s/\x93/“/g; $_value =~ s/\x94/”/g; $_value =~ s/\x96/–/g; # dashes $_value =~ s/\x97/—/g; $_value =~ s/\x7C/|/g; # pipe $_value =~ s//>/g; $_value =~ s/{/{/g; $_value =~ s/}/}/g; # only allow the known good if ($_value =~ /([\w\s\.\@\&\ \!\'\"\-\,\/\#\:\;\(\)]+)/) { $_value = $1; } else { die("(Friendly error message)"); } $_form{$_} = $_value; }