{
$date = date2sql($date_);
$sql = "INSERT INTO ".TB_PREF."voided (type, id, date_, memo_)
- VALUES ($type, $type_no, '$date', '$memo_')";
+ VALUES ($type, $type_no, ".db_escape($date).", ".db_escape($memo_).")";
db_query($sql, "could not add voided transaction entry");
}