in reply to Re^2: Special Chars in CGI form variables
in thread Special Chars in CGI form variables

Just because a form variable is "hidden" doesn't mean someone can't edit it. This is a very common misconception regarding CGI programming.
  • Comment on Re^3: Special Chars in CGI form variables