Update for apos in field name
authorSteve Sutton <steve@gaslightmedia.com>
Tue, 19 Feb 2019 18:29:21 +0000 (13:29 -0500)
committerSteve Sutton <steve@gaslightmedia.com>
Tue, 19 Feb 2019 18:29:21 +0000 (13:29 -0500)
to get O'Reilly to work for last name search.

admin/Contact/list_contact.phtml
admin/Contact/query_contact.phtml

index b36b176..0d4341f 100755 (executable)
@@ -63,7 +63,7 @@ if ($delimiter == "csv") {
 if (isset($query_string) && $query_string) {
     $query_string = strtr($query_string,"\n"," ");
     $query_string = strtr($query_string,"\t"," ");
-    $query_string = stripslashes($query_string);
+    // $query_string = stripslashes($query_string);
     $qs = $query_string;
 } elseif ($query_no) {
     $qs = "select query from query_db where id = $query_no";
index f15fbcb..ead483e 100755 (executable)
@@ -157,14 +157,14 @@ if (!$query_no) {
                 for ($c=0;$c<count($keywords);$c++) {
                     $totalc = count($keywords)-1;
                     $query_string .= $fields[$b].$operator."'".
-                        $begin.$keywords[$c].$end."'";
+                        $begin.addslashes( $keywords[$c] ).$end."'";
                     if ($c != $totalc) {
                         $query_string .= " \n$compare\t";
                     }
                 }
             } else {
                 $query_string .= $fields[$b].$operator."'".
-                    $begin.$keywords.$end."'";
+                    $begin.addslashes( $keywords ).$end."'";
             }
             if ($b != $totalb) {
                 $query_string .= " \n$compare\t";