Output encoding is context-specific

The same value needs escaping differently depending on where it is going.

Into HTML, into an attribute, into JavaScript, into a URL, into SQL. A single sanitise-on-input step cannot know the destination, which is why encoding belongs at the point of output. Getting this wrong is the reason cross-site scripting keeps appearing in applications that thought they had handled it.

More on Web application security