<h2>Send a new message to <%= display_name %></h2>
<% if params[:display_name] %>
-<p>Writing a new message to <%= params[:display_name] %></p>
+<p>Writing a new message to <%= h(params[:display_name]) %></p>
<p>TODO: drop down box of your friends</p>
<%end%>
</tr>
<tr>
<th></th>
- <td><%= f.submit_tag 'Send' %></td>
+ <td><%= submit_tag 'Send' %></td>
</tr>
</table>
<% end %>