-<h1><%= @title %></h1>
+<h1><%= h(@title) %></h1>
<span class="rsssmall"><a href="<%= url_for :action => 'georss', :display_name => @display_name, :tag => @tag %>"><img src="/images/RSS.gif" border="0" alt="RSS" /></a></span>
<% if @user.nil? or @display_name.nil? or @user.display_name != @display_name %>