LP#1822630: further sanitizing of CGI params when embedded in HTML