Bug 6632 [Signed Off] add html filter to prevent XSS