// do like this to clean and set $action $vbulletin->input->clean_array_gpc('r', array('action' => TYPE_NOHTML)); $action = $vbulletin->GPC['action']; // do like this to use $action in a query action = '" . $db->escape_string($action) . "'