unescaped apostrophes as highlighted in red:
$query = 'SELECT FROM WHERE >=Now() AND *** ='$_POST['select']'';
better would be:
$query = "SELECT * FROM **** WHERE **** >=Now() AND **** ='{$_POST['select']}'";
even better would be:
$query = "SELECT * FROM **** WHERE **** >=Now() AND **** ='".mysql_real_escape_string($_POST['select'])."'";