First thing we probably really want is what your SQL for your procedure is. At the moment we have a "works like this" statement, but that doesn't necessarily tell us much. Also, do you understand the idea of SQL Injection? Understanding is your first step.
Thom~
Excuse my typos and sometimes awful grammar. My fingers work faster than my brain does.
Larnu.uk