...
But your site has the another flaw - so called sql-injection flaw.
P.S.: I happen to protect some https enabled servers and I patched the SSL LOGN TIME AGO. We had several sql-injection attacks, none successful, but even so...
You should find a professional help, security wise.
I don't even use an sql database...
