Revision cdfebb50
Von Moritz Bunkus vor etwa 17 Jahren hinzugefügt
SL/IS.pm | ||
---|---|---|
1513 | 1513 |
} |
1514 | 1514 |
|
1515 | 1515 |
my $cid = conv_i($form->{customer_id}); |
1516 |
my $payment_id = ($form->{payment_id}) ? "($form->{payment_id} = pt.id) OR" : ""; |
|
1516 |
my $payment_id; |
|
1517 |
|
|
1518 |
if ($form->{payment_id}) { |
|
1519 |
$payment_id = "(pt.id = ?) OR"; |
|
1520 |
push @values, conv_i($form->{payment_id}); |
|
1521 |
} |
|
1522 |
|
|
1517 | 1523 |
# get customer |
1518 | 1524 |
$query = |
1519 | 1525 |
qq|SELECT |
Auch abrufbar als: Unified diff
SQL-Injection vermeiden. Fix für Revisionen 2936, 2937.