Not to excuse the obvious SQL injection vulnerability, but it looks like that is more of design firm than a web development firm. I'm guessing that they don't have the strongest developers (but then again, I would've thought Sony would've had better developers, so what do I know?).