function update_work_centre($type_id, $name, $description)
{
$sql = "UPDATE ".TB_PREF."workcentres SET name=".db_escape($name).", description=".db_escape($description)."
- WHERE id=$type_id";
+ WHERE id=".db_escape($type_id);
db_query($sql, "could not update work centre");
}
function get_work_centre($type_id)
{
- $sql = "SELECT * FROM ".TB_PREF."workcentres WHERE id=$type_id";
+ $sql = "SELECT * FROM ".TB_PREF."workcentres WHERE id=".db_escape($type_id);
$result = db_query($sql, "could not get work centre");
function delete_work_centre($type_id)
{
- $sql="DELETE FROM ".TB_PREF."workcentres WHERE id=$type_id";
+ $sql="DELETE FROM ".TB_PREF."workcentres WHERE id=".db_escape($type_id);
db_query($sql, "could not delete work centre");
}
-?>
\ No newline at end of file