There are two obvious SQL injections in there.
There are two obvious SQL injections in there.