Don't worry, the code base has been totally revamped since xMarkPro was last touched, and is no longer vulnerable to SQL / file injection.
You are right though, that code base is vulnerable. It got totally ripped to shreds when we began putting bitcoin sites on it. Nowadays, it's getting relentlessly hammered every hour on various sites for about a year now, and handles it like a champ.
Oh, and for any PHP guys out there, MeekroDB is a pretty good library to use.