diff --git a/htdocs/core/class/html.form.class.php b/htdocs/core/class/html.form.class.php
index d8a8bb8cb74..de8c4519a22 100644
--- a/htdocs/core/class/html.form.class.php
+++ b/htdocs/core/class/html.form.class.php
@@ -2496,12 +2496,12 @@ class Form
$soc = new Societe($db);
$result = $soc->fetch($socid);
if ($result > 0 && !empty($soc->default_lang)) {
- $sql .= " AND pl.lang='" . $this->db->escape($soc->default_lang) . "'";
+ $sql .= " AND pl.lang = '".$this->db->escape($soc->default_lang)."'";
} else {
- $sql .= " AND pl.lang='".$this->db->escape($langs->getDefaultLang())."'";
+ $sql .= " AND pl.lang = '".$this->db->escape($langs->getDefaultLang())."'";
}
} else {
- $sql .= " AND pl.lang='".$this->db->escape($langs->getDefaultLang())."'";
+ $sql .= " AND pl.lang = '".$this->db->escape($langs->getDefaultLang())."'";
}
}
diff --git a/htdocs/mrp/mo_movements.php b/htdocs/mrp/mo_movements.php
index 8ee47ea0bf9..f0fe25eddb6 100644
--- a/htdocs/mrp/mo_movements.php
+++ b/htdocs/mrp/mo_movements.php
@@ -812,8 +812,8 @@ if ($object->id > 0 && (empty($action) || ($action != 'edit' && $action != 'crea
// TODO Use a cache here
$sql = "SELECT label";
$sql .= " FROM ".MAIN_DB_PREFIX."product_lang";
- $sql .= " WHERE fk_product=".$objp->rowid;
- $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'";
+ $sql .= " WHERE fk_product = ".((int) $objp->rowid);
+ $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'";
$sql .= " LIMIT 1";
$result = $db->query($sql);
diff --git a/htdocs/product/index.php b/htdocs/product/index.php
index e4c81f9fd8c..e4a0bfc7421 100644
--- a/htdocs/product/index.php
+++ b/htdocs/product/index.php
@@ -342,8 +342,8 @@ if ((!empty($conf->product->enabled) || !empty($conf->service->enabled)) && ($us
if (!empty($conf->global->MAIN_MULTILANGS)) {
$sql = "SELECT label";
$sql .= " FROM ".MAIN_DB_PREFIX."product_lang";
- $sql .= " WHERE fk_product=".((int) $objp->rowid);
- $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'";
+ $sql .= " WHERE fk_product = ".((int) $objp->rowid);
+ $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'";
$resultd = $db->query($sql);
if ($resultd) {
diff --git a/htdocs/product/popuprop.php b/htdocs/product/popuprop.php
index dbffe79d0c0..9028e81a757 100644
--- a/htdocs/product/popuprop.php
+++ b/htdocs/product/popuprop.php
@@ -212,7 +212,7 @@ if ($mode && $mode != '-1') {
$sql = "SELECT label";
$sql .= " FROM ".MAIN_DB_PREFIX."product_lang";
$sql .= " WHERE fk_product = ".((int) $prodid);
- $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'";
+ $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'";
$sql .= " LIMIT 1";
$resultp = $db->query($sql);
diff --git a/htdocs/product/stock/movement_list.php b/htdocs/product/stock/movement_list.php
index 1c5bc703ca7..ed5896ca6cc 100644
--- a/htdocs/product/stock/movement_list.php
+++ b/htdocs/product/stock/movement_list.php
@@ -1160,8 +1160,8 @@ while ($i < min($num, $limit)) {
// TODO Use a cache
$sql = "SELECT label";
$sql .= " FROM ".MAIN_DB_PREFIX."product_lang";
- $sql .= " WHERE fk_product=".$objp->rowid;
- $sql .= " AND lang='".$db->escape($langs->getDefaultLang())."'";
+ $sql .= " WHERE fk_product = ".((int) $objp->rowid);
+ $sql .= " AND lang = '".$db->escape($langs->getDefaultLang())."'";
$sql .= " LIMIT 1";
$result = $db->query($sql);