I've been reading up on XSS lately, and one article mentioned PHP's htmlentities() function as a way to sanitize your data. The explanation of htmlentities() is as follows:
PHP's htmlentities() converts “all applicable characters to HTML entities.”
In reply to A Perl/CGI alternative to PHP's htmlentities()? by Spidy
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |