Note: Jefferson added Server.HTMLEncode() around calls to database fields to reduce the risk of cross-site scripting attacks.