Fixed improper sanitizing of PHP_SELF and the lack of sanitizing of QUERY_STRING...