Submitted by Cameron Eagans… on Wed, 12/28/2011 - 3:38pm Yeah, I agree. Preventing this "hack" would have been as simple as validating your inputs. Also, you shouldn't use eval(), especially on unsanitized inputs. Reply