Umm... If you're talking about the Paypal system having a security hole, I think you'll find you're mistaken

They wouldn't leave such an incredibly obvious hole.
If it's YOUR script, then just find another way of moving variables around (use sessions n' stuff...)