Oh, living crap, learn how to do it right.
Actually just don't write a single line of code for the web until you have read and understood the entirety of this page -- http://ha.ckers.org/xss.html
Then, and only then, should you think about implementing your own input sanitizer. And even at that point, don't do it, because other people have already solved the problem much better than you can.

