Presumably it's an error because in html & isn't the same as & - they both display as &, but should a link happen to have & as part of a value, using the seperator & should prevent the problem.
The -bigger- problem though was you appear to have had a file-snatching script on your account; I actually confirmed it on the server itself, so you've been permanently suspended as that'd qualify as Script Hosting and Proxy. We can't remove the suspension, so at the moment the issue with the CMS isn't nearly as big an issue.