diff options
author | einhverfr <einhverfr@4979c152-3d1c-0410-bac9-87ea11338e46> | 2007-07-27 05:23:50 +0000 |
---|---|---|
committer | einhverfr <einhverfr@4979c152-3d1c-0410-bac9-87ea11338e46> | 2007-07-27 05:23:50 +0000 |
commit | d9408a1947a99f2d6f60623374776ad30e36cf8b (patch) | |
tree | a7b4e89c4576be5d2bbc29a72be4089ae821c5b1 /LedgerSMB/OE.pm | |
parent | 98b967b036c5560d2408442e2fd5c905686b234c (diff) |
Fixing a large number of SQL errors in certain circumstances
git-svn-id: https://ledger-smb.svn.sourceforge.net/svnroot/ledger-smb/trunk@1446 4979c152-3d1c-0410-bac9-87ea11338e46
Diffstat (limited to 'LedgerSMB/OE.pm')
-rw-r--r-- | LedgerSMB/OE.pm | 8 |
1 files changed, 4 insertions, 4 deletions
diff --git a/LedgerSMB/OE.pm b/LedgerSMB/OE.pm index 2bcdbdbb..3288fe94 100644 --- a/LedgerSMB/OE.pm +++ b/LedgerSMB/OE.pm @@ -197,10 +197,10 @@ sub transactions { } if ( $form->{description} ne "" ) { - $var = $form->like( lc $form->{description} ); + $var = $dbh->quote($form->like( lc $form->{description} )); $query .= " AND o.id IN (SELECT DISTINCT trans_id FROM orderitems - WHERE lower(description) LIKE '$var')"; + WHERE lower(description) LIKE $var)"; push @queryargs, $var; } @@ -1989,12 +1989,12 @@ sub get_inventory { if ( $form->{partnumber} ne "" ) { $var = $dbh->quote( $form->like( lc $form->{partnumber} ) ); $where .= " - AND lower(p.partnumber) LIKE '$var'"; + AND lower(p.partnumber) LIKE $var"; } if ( $form->{description} ne "" ) { $var = $dbh->quote( $form->like( lc $form->{description} ) ); $where .= " - AND lower(p.description) LIKE '$var'"; + AND lower(p.description) LIKE $var"; } if ( $form->{partsgroup} ne "" ) { ( $null, $var ) = split /--/, $form->{partsgroup}; |