diff --git a/htdocs/core/class/html.form.class.php b/htdocs/core/class/html.form.class.php index d8a8bb8cb74..de8c4519a22 100644 --- a/htdocs/core/class/html.form.class.php +++ b/htdocs/core/class/html.form.class.php @@ -2496,12 +2496,12 @@ class Form $soc = new Societe($db); $result = $soc->fetch($socid); if ($result > 0 && !empty($soc->default_lang)) { - $sql .= " AND pl.lang='" . $this->db->escape($soc->default_lang) . "'"; + $sql .= " AND pl.lang = '".$this->db->escape($soc->default_lang)."'"; } else { - $sql .= " AND pl.lang='".$this->db->escape($langs->getDefaultLang())."'"; + $sql .= " AND pl.lang = '".$this->db->escape($langs->getDefaultLang())."'"; } } else { - $sql .= " AND pl.lang='".$this->db->escape($langs->getDefaultLang())."'"; + $sql .= " AND pl.lang = '".$this->db->escape($langs->getDefaultLang())."'"; } } diff --git a/htdocs/mrp/mo_movements.php b/htdocs/mrp/mo_movements.php index 8ee47ea0bf9..f0fe25eddb6 100644 --- a/htdocs/mrp/mo_movements.php +++ b/htdocs/mrp/mo_movements.php @@ -812,8 +812,8 @@ if ($object->id > 0 && (empty($action) || ($action != 'edit' && $action != 'crea // TODO Use a cache here $sql = "SELECT label"; $sql .= " FROM ".MAIN_DB_PREFIX."product_lang"; - $sql .= " WHERE fk_product=".$objp->rowid; - $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'"; + $sql .= " WHERE fk_product = ".((int) $objp->rowid); + $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'"; $sql .= " LIMIT 1"; $result = $db->query($sql); diff --git a/htdocs/product/index.php b/htdocs/product/index.php index e4c81f9fd8c..e4a0bfc7421 100644 --- a/htdocs/product/index.php +++ b/htdocs/product/index.php @@ -342,8 +342,8 @@ if ((!empty($conf->product->enabled) || !empty($conf->service->enabled)) && ($us if (!empty($conf->global->MAIN_MULTILANGS)) { $sql = "SELECT label"; $sql .= " FROM ".MAIN_DB_PREFIX."product_lang"; - $sql .= " WHERE fk_product=".((int) $objp->rowid); - $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'"; + $sql .= " WHERE fk_product = ".((int) $objp->rowid); + $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'"; $resultd = $db->query($sql); if ($resultd) { diff --git a/htdocs/product/popuprop.php b/htdocs/product/popuprop.php index dbffe79d0c0..9028e81a757 100644 --- a/htdocs/product/popuprop.php +++ b/htdocs/product/popuprop.php @@ -212,7 +212,7 @@ if ($mode && $mode != '-1') { $sql = "SELECT label"; $sql .= " FROM ".MAIN_DB_PREFIX."product_lang"; $sql .= " WHERE fk_product = ".((int) $prodid); - $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'"; + $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'"; $sql .= " LIMIT 1"; $resultp = $db->query($sql); diff --git a/htdocs/product/stock/movement_list.php b/htdocs/product/stock/movement_list.php index 1c5bc703ca7..ed5896ca6cc 100644 --- a/htdocs/product/stock/movement_list.php +++ b/htdocs/product/stock/movement_list.php @@ -1160,8 +1160,8 @@ while ($i < min($num, $limit)) { // TODO Use a cache $sql = "SELECT label"; $sql .= " FROM ".MAIN_DB_PREFIX."product_lang"; - $sql .= " WHERE fk_product=".$objp->rowid; - $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'"; + $sql .= " WHERE fk_product = ".((int) $objp->rowid); + $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'"; $sql .= " LIMIT 1"; $result = $db->query($sql);