Use
PHP Code:
$vbulletin->db->escape_string($var)
when querying.
So
PHP Code:
$user = $db->query_first("
SELECT userid, username
FROM " . TABLE_PREFIX . "user
WHERE username = '". $vbulletin->GPC['awardusername'] ."'
");
Would change to:
PHP Code:
$user = $db->query_first("
SELECT userid, username
FROM " . TABLE_PREFIX . "user
WHERE username = '". $vbulletin->db->escape_string($vbulletin->GPC['awardusername'])."'
");