summaryrefslogtreecommitdiff
path: root/LedgerSMB/OE.pm
diff options
context:
space:
mode:
authoreinhverfr <einhverfr@4979c152-3d1c-0410-bac9-87ea11338e46>2007-07-27 05:23:50 +0000
committereinhverfr <einhverfr@4979c152-3d1c-0410-bac9-87ea11338e46>2007-07-27 05:23:50 +0000
commitd9408a1947a99f2d6f60623374776ad30e36cf8b (patch)
treea7b4e89c4576be5d2bbc29a72be4089ae821c5b1 /LedgerSMB/OE.pm
parent98b967b036c5560d2408442e2fd5c905686b234c (diff)
Fixing a large number of SQL errors in certain circumstances
git-svn-id: https://ledger-smb.svn.sourceforge.net/svnroot/ledger-smb/trunk@1446 4979c152-3d1c-0410-bac9-87ea11338e46
Diffstat (limited to 'LedgerSMB/OE.pm')
-rw-r--r--LedgerSMB/OE.pm8
1 files changed, 4 insertions, 4 deletions
diff --git a/LedgerSMB/OE.pm b/LedgerSMB/OE.pm
index 2bcdbdbb..3288fe94 100644
--- a/LedgerSMB/OE.pm
+++ b/LedgerSMB/OE.pm
@@ -197,10 +197,10 @@ sub transactions {
}
if ( $form->{description} ne "" ) {
- $var = $form->like( lc $form->{description} );
+ $var = $dbh->quote($form->like( lc $form->{description} ));
$query .= " AND o.id IN (SELECT DISTINCT trans_id
FROM orderitems
- WHERE lower(description) LIKE '$var')";
+ WHERE lower(description) LIKE $var)";
push @queryargs, $var;
}
@@ -1989,12 +1989,12 @@ sub get_inventory {
if ( $form->{partnumber} ne "" ) {
$var = $dbh->quote( $form->like( lc $form->{partnumber} ) );
$where .= "
- AND lower(p.partnumber) LIKE '$var'";
+ AND lower(p.partnumber) LIKE $var";
}
if ( $form->{description} ne "" ) {
$var = $dbh->quote( $form->like( lc $form->{description} ) );
$where .= "
- AND lower(p.description) LIKE '$var'";
+ AND lower(p.description) LIKE $var";
}
if ( $form->{partsgroup} ne "" ) {
( $null, $var ) = split /--/, $form->{partsgroup};