Security statements update against sql injection attacks.
[fa-stable.git] / purchasing / inquiry / supplier_allocation_inquiry.php
index 55ab1678c676deb0b6142dd8a9f02664ea41f5e5..1782ef075a495b3fb102901af348cbd9e9b9cdf2 100644 (file)
@@ -141,7 +141,7 @@ function fmt_credit($row)
        AND trans.tran_date >= '$date_after'
        AND trans.tran_date <= '$date_to'";
        if ($_POST['supplier_id'] != reserved_words::get_all())
-               $sql .= " AND trans.supplier_id = '" . $_POST['supplier_id'] . "'";
+               $sql .= " AND trans.supplier_id = ".db_escape($_POST['supplier_id']);
        if (isset($_POST['filterType']) && $_POST['filterType'] != reserved_words::get_all())
        {
                if (($_POST['filterType'] == '1') || ($_POST['filterType'] == '2'))