Setting tools table is prone to SQL injection, because most of them are dumped in the SQL command without any validation.