$id = db_escape($id);
$sql = "SELECT SUM(amount) FROM ".TB_PREF."gl_trans WHERE tran_date >= '" .
date2sql($from) . "' AND
- tran_date <= '" . date2sql($to) . "' AND (dimension_id = " .
- db_escape($id)." OR dimension2_id = " .db_escape($id).")";
+ tran_date <= '" . date2sql($to) . "' AND (dimension_id = $id OR dimension2_id = $id)";
$res = db_query($sql, "Sum of transactions could not be calculated");
$row = db_fetch_row($res);
$_POST['TransToDate'] = Today();
date_cells(_("from:"), 'TransFromDate');
date_cells(_("to:"), 'TransToDate');
-submit_cells('Show',_("Show"), '', false, 'default');
+submit_cells('Show',_("Show"), '', false);
end_row();