webmail interface

I'm currently working on a webmail interface to go along with a few
other scripts, and recalling MS's hotmail security holes, have been
wondering what tags/strings should be avoided.  

I'm interested in keeping things sane - avoiding people putting in
meta tags, images, and mainly java[script].

What should I watch out for?  Are there any good open-source systems
that do this?

Peace
-Brian

Received on Sunday, 18 February 2001 14:48:12 UTC