i was referring to the feature that allows code insertion, not the button tag. cuz the comment box allows this inserting of code. like, why is this allowed? i assume it wouldn't be if you could use it to do xss attacks. and it doesn't seem to work, at least with html, unless i'm missing...