Just took a look at the new zip ;)
Your search box can now only be a number as your run it with (int) and not mysql_real_escape_string() also want to add into to all ints to as a safe measure.
Might also want to protect those with register_globals on in functions/cookie.php
|