Fixed error on inserting refs with single quotes.
[fa-stable.git] / sql / alter2.2.php
index f35867199dcdb8409d4c1cbdfaa2da22efd62180..386e9623ec7d861d4919acd18d48cb219fe6fce1 100644 (file)
@@ -56,7 +56,7 @@ class fa2_2 {
                        if (db_num_rows($result)) {
                                while ($row = db_fetch($result)) {
                                        $res2 = db_query("INSERT INTO {$pref}refs VALUES("
-                                               . $row['id'].",".$typeno.",'".$row['ref']."')");
+                                               . $row['id'].",".$typeno.",'".addslashes($row['ref'])."')");
                                        if (!$res2) {
                                                display_error(_("Cannot copy references from $tbl")
                                                        .':<br>'. db_error_msg($db));