You can try trace it by doing this:
1) make sure you have in comment_form.html:
<?php
global $mode;
?>
<input type="hidden" name="mode" value="<?=$mode;?>" />
2) add this at the end of global.php:
if ((isset($_POST['mode']) && $_POST['mode'] == "yourtext") || (isset($_GET['mode']) && $_GET['mode'] == "yourtext"))
{
function _e($head = "", $txt = "")
{
echo "<pre>";
echo "<b>".$head."</b>\n\n";
echo htmlspecialchars(print_r($txt,1));
echo "\n--------------\n</pre>";
}
_e("_GET", $_GET);
_e("HTTP_GET_VARS", @$HTTP_GET_VARS);
_e("_POST", $_POST);
_e("HTTP_POST_VARS", @$HTTP_POST_VARS);
_e("_SERVER", $_SERVER);
}
(replace "yourtext" with something only you would know)
3) open details page with &mode=yourtext and post a comment
see what _POST and HTTP_POST_VARS will show.