"<form name=\"prefform\" action=\"set_preferences\" "
"method=\"post\">\n"
"<table border=0 cellspacing=5 cellpadding=5>\n");
+ wprintf("<input type=\"hidden\" name=\"nonce\" value=\"%ld\">\n", WC->nonce);
/**
* Room list view
wprintf("<tr><td>");
wprintf(_("Default character set for email headers:"));
wprintf("</td><td>");
- wprintf("<input type=\"text\" NAME=\"default_header_charset\" MAXLENGTH=\"32\" VALUE=\"%s\">", buf);
+ wprintf("<input type=\"text\" NAME=\"default_header_charset\" MAXLENGTH=\"32\" VALUE=\"");
+ escputs(buf);
+ wprintf("\">");
wprintf("</td></tr>");
/** submit buttons */