X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;ds=sidebyside;f=reporting%2Frep104.php;h=d6249e0d5a5dfeaf109b421c98655f56bcb3f81e;hb=af78fbb535a6fedbc2eb70a26ddc39739be2b986;hp=53d8fea1df6d438c4bfdd79e1fa27afdd993d297;hpb=80dd97a37f674cc3691fa04af4c29607067566b2;p=fa-stable.git diff --git a/reporting/rep104.php b/reporting/rep104.php index 53d8fea1..d6249e0d 100644 --- a/reporting/rep104.php +++ b/reporting/rep104.php @@ -40,7 +40,7 @@ function fetch_items($category=0) ".TB_PREF."stock_category WHERE ".TB_PREF."stock_master.category_id=".TB_PREF."stock_category.category_id"; if ($category != 0) - $sql .= " AND ".TB_PREF."stock_category.category_id = '$category'"; + $sql .= " AND ".TB_PREF."stock_category.category_id = ".db_escape($category); $sql .= " ORDER BY ".TB_PREF."stock_master.category_id, ".TB_PREF."stock_master.stock_id"; @@ -57,7 +57,7 @@ function get_kits($category=0) ON i.category_id=c.category_id"; $sql .= " WHERE !i.is_foreign AND i.item_code!=i.stock_id"; if ($category != 0) - $sql .= " AND c.category_id = '$category'"; + $sql .= " AND c.category_id = ".db_escape($category); $sql .= " GROUP BY i.item_code"; return db_query($sql,"No kits were returned"); }