@ -23,7 +23,7 @@
$s = mysql_real_escape_string($_REQUEST['s']);
$id = mysql_real_escape_string(strip_tags($_REQUEST['id']));
echo "parent._ac_rpc('$id',";
echo "parent._ac_rpc('".sanitizeHTML($id)."',";
$bits = explode(",", $s);