I'll have to check this out, in the meantime all places where the radio station names are used (and other info that the users can add to stations) need to be surrounded by htmlentities() (which I would think I did).
Also this would only be a problem if you allow other people to add stations, and if it's true of course.
You could disallow everyone to add stations but you for the time being.
|