From: <ice...@us...> - 2013-08-27 02:55:26
|
Revision: 6298 http://sourceforge.net/p/web-erp/reponame/6298 Author: icedlava Date: 2013-08-27 02:55:22 +0000 (Tue, 27 Aug 2013) Log Message: ----------- Escape for special characters in transfer from location name. Modified Paths: -------------- trunk/StockLocTransferReceive.php Modified: trunk/StockLocTransferReceive.php =================================================================== --- trunk/StockLocTransferReceive.php 2013-08-27 02:24:06 UTC (rev 6297) +++ trunk/StockLocTransferReceive.php 2013-08-27 02:55:22 UTC (rev 6298) @@ -206,7 +206,7 @@ '" . $_SESSION['Transfer']->StockLocationTo . "', '" . $SQLTransferDate . "', '" . $PeriodNo . "', - '" . _('From') . ' ' . $_SESSION['Transfer']->StockLocationFromName ."', + '" . _('From') . ' ' . mysql_real_escape_string($_SESSION['Transfer']->StockLocationFromName) ."', '" . round($TrfLine->Quantity, $TrfLine->DecimalPlaces) . "', '" . round($QtyOnHandPrior + $TrfLine->Quantity, $TrfLine->DecimalPlaces) . "' )"; |