Fix: problme d'apostrophe

prvoir la cration d'une classe pour sparer les requtes sql
This commit is contained in:
Regis Houssin 2007-09-20 19:26:55 +00:00
parent c037b87f58
commit 89c17d1875

View File

@ -100,7 +100,7 @@ if ($_POST["action"] == "update")
$dateop = $_POST["dateoyear"].'-'.$_POST["dateomonth"].'-'.$_POST["dateoday"];
$dateval= $_POST["datevyear"].'-'.$_POST["datevmonth"].'-'.$_POST["datevday"];
$sql = "UPDATE ".MAIN_DB_PREFIX."bank";
$sql.= " SET label='".$_POST["label"]."',";
$sql.= " SET label='".addslashes($_POST["label"])."',"; // Todo: créer une classe pour séparer les requêtes sql
if (isset($_POST['amount'])) $sql.=" amount='$amount',";
$sql.= " dateo = '".$dateop."', datev = '".$dateval."',";
$sql.= " fk_account = ".$_POST['accountid'];