Skip to content
Snippets Groups Projects
Commit 02235545 authored by Robert Anderson's avatar Robert Anderson
Browse files

Use db->quote()

parent 1dee1418
No related branches found
No related tags found
No related merge requests found
......@@ -117,7 +117,7 @@ function displayDetails() {
FROM
${DB_TABLE_PREFIX}user_attributes
WHERE
UserID = '$userID'
UserID = ".$db->quote($userID)."
";
$res = $db->query($sql);
......@@ -144,8 +144,8 @@ function displayDetails() {
${DB_TABLE_PREFIX}topups
WHERE
${DB_TABLE_PREFIX}topups_summary.TopupID = ${DB_TABLE_PREFIX}topups.ID
AND ${DB_TABLE_PREFIX}topups.UserID = '$userID'
AND ${DB_TABLE_PREFIX}topups_summary.PeriodKey = $currentMonth
AND ${DB_TABLE_PREFIX}topups.UserID = ".$db->quote($userID)."
AND ${DB_TABLE_PREFIX}topups_summary.PeriodKey = ".$db->quote($currentMonth)."
AND ${DB_TABLE_PREFIX}topups_summary.Depleted = 0
ORDER BY
${DB_TABLE_PREFIX}topups.Timestamp
......@@ -172,9 +172,9 @@ function displayDetails() {
FROM
${DB_TABLE_PREFIX}topups
WHERE
${DB_TABLE_PREFIX}topups.UserID = '$userID'
AND ${DB_TABLE_PREFIX}topups.ValidFrom >= $thisMonthUnixTime
AND ${DB_TABLE_PREFIX}topups.ValidTo > $now
${DB_TABLE_PREFIX}topups.UserID = ".$db->quote($userID)."
AND ${DB_TABLE_PREFIX}topups.ValidFrom >= ".$db->quote($thisMonthUnixTime)."
AND ${DB_TABLE_PREFIX}topups.ValidTo > ".$db->quote($now)."
AND ${DB_TABLE_PREFIX}topups.Depleted = 0
ORDER BY
${DB_TABLE_PREFIX}topups.Timestamp
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment