What should be done to avoid Script Injection?

To avoid script injection, following things can be done

1. Don't allow user to enter < and > characters as input.
2. Always Encode user's input and then store in the database.

