PHP : XSS due to insufficient validation