
¿Qué os parece para evitar XSS?
function antihack($s, $t){
//$t == 1, numero 2 == string
if($t==1){
return (int)$s;
} else{
if(get_magic_quotes_gpc())
$s = stripslashes($s);
if(function_exists("mysql_real_escape_string"))
$s = mysql_real_escape_string( $s );
else $s = addslashes( $s );
$s = htmlspecialchars($s, ENT_QUOTES, 'UTF-8');
return $s;
}
}