I recently noticed that I had a big hole in my application because I had done something like:
\" />
Potentially Dangerous HTML Tags:
While not an exhaustive list, the following commonly used HTML tags could allow a malicious user to inject script code: