diff --git a/modules/registrars/cozaepp/cozaeppsync.php b/modules/registrars/cozaepp/cozaeppsync.php
index 142839bdab43906093fdaa1daffe13fd28d715a1..e3791742c2760e51da5bd24a12d1c65db92e6eae 100644
--- a/modules/registrars/cozaepp/cozaeppsync.php
+++ b/modules/registrars/cozaepp/cozaeppsync.php
@@ -110,19 +110,34 @@ foreach($domains as $domain) {
 
 
 	# This is the template we going to use below for our updates
-	$querytemplate = "UPDATE tbldomains SET status = %s, registrationdate = %s, expirydate = %s, nextduedate = %s WHERE domain = %s";
+	$querytemplate = "UPDATE tbldomains SET status = '%s', registrationdate = '%s', expirydate = '%s', nextduedate = '%s' WHERE domain = '%s'";
 
 	# Check status and update
 	if ($statusres == "ok") {
-		mysql_query(sprintf($querytemplate,"Active",$createdate,$nextduedate,$nextduedate,$domain));
+		mysql_query(sprintf($querytemplate,"Active",
+				mysql_real_escape_string($createdate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($domain)
+		));
 		echo "Updated $domain expiry to $nextduedate\n";
 
 	} elseif ($statusres == "serverHold") {
-		mysql_query(sprintf($querytemplate,"Pending",$createdate,$nextduedate,$nextduedate,$domain));
+		mysql_query(sprintf($querytemplate,"Pending",
+				mysql_real_escape_string($createdate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($domain)
+		));
 		echo "Domain $domain is PENDING (Registration: $createdate, Expiry: $nextduedate)\n";
 
 	} elseif ($statusres == "expired") {
-		mysql_query(sprintf($querytemplate,"Expired",$createdate,$nextduedate,$nextduedate,$domain));
+		mysql_query(sprintf($querytemplate,"Expired",
+				mysql_real_escape_string($createdate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($nextduedate),
+				mysql_real_escape_string($domain)
+		));
 		echo "Domain $domain is EXPIRED (Registration: $createdate, Expiry: $nextduedate)\n";
 	} else {
 		echo "Domain $domain has unknown status '$statusres' (File a bug report here: http://devlabs.linuxassist.net/projects/whmcs-coza-epp/issues/new)\n";