still just XSS

anyway fixed via str_replace

i dont love "too much" hackers ...