secure $cgi->param calls (and include to <& &>)