in reply to Web Security

Try Data::FormValidator or CGI::Untaint or CGI::FormBuilder