PHP is (IMHO) a better choice. You still need to be sure that the script strips HTML tags and does not allow new lines to be entered in a way that would allow them to launch an email using the Cc function from your site.
__________________
DrTandem's San Diego Web Page Design, drtandem.com
|