Respuesta :

Not sanitizing input before passing it into a database query.
good job