@Russ yeah, I meant similar to XSS really - untrusted input getting passed and parsed And no way to escape. Thanks for explanation.