i think that is the site trying to parse the url. not the code.
Possibly, we'll need the OP to confirm that :)
Also, I will point out that there is no sanitation of the values.. Never a good idea to put POST data directly into SQL or such without checking what the user has actually entered.