This code's pretty riddled with SQL injection vulnerabilities. Can't imagine anyone recommending use of this for new projects.
For a single instance, https://github.com/WhatCD/Gazelle/blob/master/sections/user/...
The $UserId variable, which is used throughout the queries within this file, is set by an unfiltered GET variable.