fixing a sql query not using prepare(?) & execute($var) method
authortipaul <tipaul>
Tue, 28 Jan 2003 14:53:30 +0000 (14:53 +0000)
committertipaul <tipaul>
Tue, 28 Jan 2003 14:53:30 +0000 (14:53 +0000)
C4/Catalogue.pm

index 27a2995..7e3835c 100644 (file)
@@ -334,11 +334,11 @@ sub receiveorder {
   my $sth=$dbh->prepare($query);
   $sth->execute;
   $sth->finish;
-  $query="update aqorderbreakdown set bookfundid=$bookfund where
-  ordernumber=$ordnum";
+  $query="update aqorderbreakdown set bookfundid=? where
+  ordernumber=?";
   $sth=$dbh->prepare($query);
 #  print $query;
-  $sth->execute;
+  $sth->execute($bookfund,$ordnum);
   $sth->finish;
 }