\r
<div class="row">\r
<div class="required" title="<?php echo _AT('required_field'); ?>">*</div><label for="title"><?php echo _AT('title'); ?></label><br />\r
- <input type="text" name="title" id="title" value="<?php echo $row['title']; ?>" size="20" maxlength="40" />\r
+ <input type="text" name="title" id="title" value="<?php echo htmlspecialchars($row['title']); ?>" size="20" maxlength="40" />\r
</div>\r
\r
<div class="row">\r
<label for="description"><?php echo _AT('description'); ?>:</label><br />\r
- <textarea name="description" id="description" cols="10" rows="2"><?php echo $row['description']; ?></textarea>\r
+ <textarea name="description" id="description" cols="10" rows="2"><?php echo htmlspecialchars($row['description']); ?></textarea>\r
</div>\r
\r
<div class="row">\r