mysql_real_escape_string(htmlentities(XSS_CLEAN(filter_input('INPUT_POST', $str, FILTER_SANITIZE_ENCODED )), ENT_QUOTES), $dbobj));