Hacker News new | ask | show | jobs
by Flam 4335 days ago
This is a common mistake tons of developers do.

Pro-tip: Escape all user input either when it's going into the system or when it's going back out to be displayed!