	function checkF() {
	var s = document.searchf.q.value;

	s = s.replace(/&/gi, "and");

	s = s.replace(/%3C/gi, "");
	s = s.replace(/%2F/gi, "");
	s = s.replace(/%2F/gi, "");
	s = s.replace(/%3E/gi, "");
	s = s.replace(/%28/gi, "");
	s = s.replace(/%29/gi, "");
	s = s.replace(/%5B/gi, "");
	s = s.replace(/%5D/gi, "");
	s = s.replace(/%27/gi, "");
	s = s.replace(/%3B/gi, "");
	s = s.replace(/%3A/gi, "");

	s = s.replace(/[[]/g,"");
	s = s.replace(/[]]/g,"");
	s = s.replace(/[;]/g,"");
	//s = s.replace(/[:]/g,"");
	s = s.replace(/[']/g,"");
	s = s.replace(/[/]/g,"");
	s = s.replace(/[(]/g,"");
	s = s.replace(/[)]/g,"");
	s = s.replace(/[<]/g,"");
	s = s.replace(/[>]/g,"");

	document.searchf.q.value = s;

	return true;
}

function xss_fix(frm)
{
	for(i=0; i<frm.elements.length; i++)
	{
		frm.elements[i].value = xss_check(frm.elements[i].value);
	}	

	return true;
}

function xss_check(e) 
{
	var s = e;

	s = s.replace(/&/gi, "and");

	s = s.replace(/%3C/gi, "");
	s = s.replace(/%2F/gi, "");
	s = s.replace(/%2F/gi, "");
	s = s.replace(/%3E/gi, "");
	s = s.replace(/%28/gi, "");
	s = s.replace(/%29/gi, "");
	s = s.replace(/%5B/gi, "");
	s = s.replace(/%5D/gi, "");
	s = s.replace(/%27/gi, "");
	s = s.replace(/%3B/gi, "");
	s = s.replace(/%3A/gi, "");

	s = s.replace(/[[]/g,"");
	s = s.replace(/[]]/g,"");
	s = s.replace(/[;]/g,"");
	//s = s.replace(/[:]/g,"");
	s = s.replace(/[']/g,"");
	s = s.replace(/[/]/g,"");
	s = s.replace(/[(]/g,"");
	s = s.replace(/[)]/g,"");
	s = s.replace(/[<]/g,"");
	s = s.replace(/[>]/g,"");

	return s;
}
