From bf0a634a63ed881399e3ddfe66ef0be266f424e7 Mon Sep 17 00:00:00 2001 From: Janusz Dobrowolski Date: Thu, 11 Sep 2008 21:58:08 +0000 Subject: [PATCH] Added missed db_escape on person_id. --- gl/includes/db/gl_db_bank_trans.inc | 2 +- gl/includes/db/gl_db_trans.inc | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/gl/includes/db/gl_db_bank_trans.inc b/gl/includes/db/gl_db_bank_trans.inc index 6aebe6f4..200277fb 100644 --- a/gl/includes/db/gl_db_bank_trans.inc +++ b/gl/includes/db/gl_db_bank_trans.inc @@ -29,7 +29,7 @@ function add_bank_trans($type, $trans_no, $bank_act, $ref, $date_, $bank_trans_t trans_date, bank_trans_type_id, amount, person_type_id, person_id) "; $sql .= "VALUES ($type, $trans_no, '$bank_act', ".db_escape($ref).", '$sqlDate', '$bank_trans_type_id', - $amount_bank, $person_type_id, '$person_id')"; + $amount_bank, $person_type_id, ". db_escape($person_id).")"; if ($err_msg == "") $err_msg = "The bank transaction could not be inserted"; diff --git a/gl/includes/db/gl_db_trans.inc b/gl/includes/db/gl_db_trans.inc index ecd12fae..79b03d80 100644 --- a/gl/includes/db/gl_db_trans.inc +++ b/gl/includes/db/gl_db_trans.inc @@ -40,7 +40,7 @@ function add_gl_trans($type, $trans_id, $date_, $account, $dimension, $dimension '$account', $dimension, $dimension2, ".db_escape($memo_).", $amount_in_home_currency"; if ($person_type_id != null) - $sql .= ", $person_type_id, '$person_id'"; + $sql .= ", $person_type_id, ". db_escape($person_id); $sql .= ") "; -- 2.30.2