- fixed some possible XSS with PHP_SELF (PATH_INFO) - commented out some use of PATH_INFO ... needs further testing