'itemid' was not properly sanitized which would lead to an SQL injection flaw. ok robert@ (MAINTAINER)