$getbox = mysql_query("SELECT * FROM ".$db_prefix."mesage WHERE id = '".$_GET['box']."'");
$boxx = mysql_fetch_array($getbox);
и заменяш с
Код:
$getbox = mysql_query("SELECT * FROM ".$db_prefix."mesage WHERE id = '".intval($_GET['box'])."'");
if(mysql_num_rows($getbox) < 1) die("Не е намерено съобщението!");
$boxx = mysql_fetch_array($getbox);