There is much to review in the php setup to make sure your scripts are secure. Make sure that you have set register_globals=OFF. For more ways to make your PHP scripts secure, see this tutorial: http://www.webhostingusers.com/a/e80000/48/288/54/11/Tutorials/Security/Secure-Your-PHP-Scripts