Here's a great example of SQL Injection:,MD5('asdf')),NULL,NULL,NULL,NULL%20--

The new years filter URL variable is not cleaned up before it's put into the SQL. Notice the double dash closing off the rest of the SQL from messing up the injection.


