Okay, although I didn't have a chance to find exactly where that variable is, (ie if in admin panel or not), but I didn't find it in a code search. So my guess is that I was wrong above.
My suggestion might be to reinstall the files. Something doesn't seem right to me about sending a variable to the SQL statement rather than the value being substituted for the variable.
Bookmarks