Prevent XSS / arbitrary HTML injection via unescaped "rs" parameter. Proof-of-Concept...