You could start off with basic data validation. Pumping all of the fields into the db without checking even one of them? That's just asking for injection.
Reputation Points: 232
Solved Threads: 137
Practically a Master Poster
Offline 665 posts
since Nov 2007