As proposed by Steve Lionel the query for the zone_code was made more secure (only file changed includes/modules/shipping/upsxml.php)

More...