Security: SQL Injection prone
Brought to you by:
hollow_
If you go to a URL like :
/ppm_account_view.php?id='1
You see :
query failed: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1' at line 1
Hence, it's open to SQL injection vulnerabilities.
Logged In: YES
user_id=1293131
Originator: NO
looks like you may be correct, as far as I can find the class simply adds the value to the sql statement before executing. Try surrounding all instances of $_POST or $_GET with htmlentities().
Logged In: YES
user_id=1293131
Originator: NO
Correction, use mysql_real_escape_string()