Damn...little to no help on these forums, huh?
Anyway, hopefully this will help someone else out. Here's what I did to stop these SQL errors:
File: class.ticket.php
Line: around 613 in v1.6 Stable
Action: change the "message=" line to something like this
',message='.db_input(Format:(preg_replace("/\xa0/"," ",preg_replace("/\s/"," ",str_ireplace("\xA0"," ",str_ireplace("=A0"," ",str_replace(chr(160)," ",$msg))))))). //Tags/code stripped...meaning client can not send in code..etc
I'm sure there's a better way to solve this problem and I hope the developers figure it out before the next release.
________
(volcano vaporizer)