I see you're using a mysql function. Where is the code for it?
I see you're using a mysql function. Did you allow the user to execute it?
I see you're trying to get multiple columns returned from a mysql function. This is not possible.
I see your code is not properly indented, making some if()'s do different things than you think they do.
I see you're using sprintf plus cod2 string concat. This is weird.