Doesn't look like this 'Derek' guy knows how to sanitize input properly: http://166.78.158.209/page?id=upolrzwhns
This is just sad.
This is just sad.
I can understand that this might be a hassle if you've written this app in COBOL, or some other word-heavy language. In which case, my most sincere condolences.
Nonetheless, you really should make sure that input is sanitized. XSS attacks are a nasty thing.