HTML injection via insecure parameter [https://www.ubercarshare.com/]