You are getting quantity and other stuff from url, that is not good practice in my view, url tempering can be done (although you are not putting anything secret in url), XSS attacks are common taking place from both urls and input fields. I would suggest you to use session instead. Of course nothing is perfect, but it makes it less vulnerable.
Sarfraz
2010-02-23 05:59:24