%3Cscript%3Ealert%28123%29%3C%2Fscript%3E - URL- <script>alert(123);</script>. , < , %3C. PHP <, - .
, , ; %3C , <. , XSS.
XSS. zend. StripTags, StringTrim HtmlEntities .
, XSS. , .
- , XSS.
. , , O'Brien. <script>, . HTML-, , , HTML-? , , 'Fish&Chips', HTML- HTML.
HTML- . , (, , , SQL-escape- , ). HTML, :
Name: <?php echo htmlspecialchars($row['name']); ?>
echo "Name: $name";, , , .
: h, htmlspecialchars . htmlentities, - -ASCII-, , $charset.
(, Zend_View, $this->escape().)
, , , , , . , , , , - HTML, SQL, JavaScript , .