$sql .= ")) AS OutStanding
FROM ".TB_PREF."debtor_trans
WHERE ".TB_PREF."debtor_trans.tran_date < '$to'
- AND ".TB_PREF."debtor_trans.debtor_no = '$debtorno'
+ AND ".TB_PREF."debtor_trans.debtor_no = ".db_escape($debtorno)."
AND ".TB_PREF."debtor_trans.type <> ".ST_CUSTDELIVERY." GROUP BY debtor_no";
$result = db_query($sql,"No transactions were returned");
FROM ".TB_PREF."debtor_trans
WHERE ".TB_PREF."debtor_trans.tran_date >= '$from'
AND ".TB_PREF."debtor_trans.tran_date <= '$to'
- AND ".TB_PREF."debtor_trans.debtor_no = '$debtorno'
+ AND ".TB_PREF."debtor_trans.debtor_no = ".db_escape($debtorno)."
AND ".TB_PREF."debtor_trans.type <> ".ST_CUSTDELIVERY."
ORDER BY ".TB_PREF."debtor_trans.tran_date";
$sql = "SELECT debtor_no, name, curr_code FROM ".TB_PREF."debtors_master ";
if ($fromcust != ALL_NUMERIC)
- $sql .= "WHERE debtor_no=$fromcust ";
- $sql .= "ORDER BY name";
+ $sql .= "WHERE debtor_no=".db_escape($fromcust);
+ $sql .= " ORDER BY name";
$result = db_query($sql, "The customers could not be retrieved");
while ($myrow = db_fetch($result))