X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;ds=sidebyside;f=sales%2Fincludes%2Fdb%2Fcredit_status_db.inc;h=ab0ade98765ddc20d025cf07fb5ba723eaafb826;hb=3cf9ab70d79ebd01b13b6cc0c9366ccb5b8c496a;hp=d59785a365cf5ad00dcbbc0471dc662030e4ddc5;hpb=3bf71dd6f93ecac6b93fe98d23b247869cbeb720;p=fa-stable.git diff --git a/sales/includes/db/credit_status_db.inc b/sales/includes/db/credit_status_db.inc index d59785a3..ab0ade98 100644 --- a/sales/includes/db/credit_status_db.inc +++ b/sales/includes/db/credit_status_db.inc @@ -12,7 +12,7 @@ function add_credit_status($description, $disallow_invoicing) { $sql = "INSERT INTO ".TB_PREF."credit_status (reason_description, dissallow_invoices) - VALUES (".db_escape($description).",$disallow_invoicing)"; + VALUES (".db_escape($description).",".db_escape($disallow_invoicing).")"; db_query($sql, "could not add credit status"); } @@ -20,7 +20,7 @@ function add_credit_status($description, $disallow_invoicing) function update_credit_status($status_id, $description, $disallow_invoicing) { $sql = "UPDATE ".TB_PREF."credit_status SET reason_description=".db_escape($description).", - dissallow_invoices=$disallow_invoicing WHERE id=$status_id"; + dissallow_invoices=".db_escape($disallow_invoicing)." WHERE id=".db_escape($status_id); db_query($sql, "could not update credit status"); } @@ -35,7 +35,7 @@ function get_all_credit_status($all=false) function get_credit_status($status_id) { - $sql = "SELECT * FROM ".TB_PREF."credit_status WHERE id=$status_id"; + $sql = "SELECT * FROM ".TB_PREF."credit_status WHERE id=".db_escape($status_id); $result = db_query($sql, "could not get credit status"); @@ -44,7 +44,7 @@ function get_credit_status($status_id) function delete_credit_status($status_id) { - $sql="DELETE FROM ".TB_PREF."credit_status WHERE id=$status_id"; + $sql="DELETE FROM ".TB_PREF."credit_status WHERE id=".db_escape($status_id); db_query($sql, "could not delete credit status"); }