Redbeard wrote:I followed that, but why do they not display correctly sometimes?
It is like this:
1. You enter them in the user form and click 'save' - they are encoded once and display correctly
2. You edit your profile, they appear incorrectly in the user form (in encoded form), you click save and it will then save the incorrect version as they are encoded again, so are double encoded
3. You notice the error, so edit your profile again, replacing the invalid encoded version with the original version again.
It is a bit of a glitch but one that is infrequent enough that I stay on the side of total safety and put up with. Without adequate encoding, people could put in locations like "><script.... which would then allow scripts to be executed and user logins changed or stolen.>