Changed database access to PDO using prepared statements
This commit is contained in:
@@ -14,22 +14,14 @@ $assetclassgroup_id = sanitize($_GET['assetclassgroup_id']);
|
||||
$smarty->assign("scripts", 'jscolor.js');
|
||||
include("header.php");
|
||||
|
||||
$smarty->assign($lang);
|
||||
$sql = "SELECT assetclassgroup_id AS id, assetclassgroup_name AS name,
|
||||
assetclassgroup_color AS color
|
||||
FROM assetclassgroup
|
||||
WHERE assetclassgroup_id=?";
|
||||
$sth = $dbh->prepare($sql);
|
||||
$sth->execute([$assetclassgroup_id]);
|
||||
|
||||
$query = "SELECT
|
||||
assetclassgroup_id,
|
||||
assetclassgroup_name,
|
||||
assetclassgroup_color
|
||||
FROM
|
||||
assetclassgroup
|
||||
WHERE
|
||||
assetclassgroup_id=" . $assetclassgroup_id;
|
||||
|
||||
$assetclassgroup = $db->db_select($query);
|
||||
|
||||
$smarty->assign("assetclassgroup_id", $assetclassgroup[0]['assetclassgroup_id']);
|
||||
$smarty->assign("assetclassgroup_name", $assetclassgroup[0]['assetclassgroup_name']);
|
||||
$smarty->assign("assetclassgroup_color", $assetclassgroup[0]['assetclassgroup_color']);
|
||||
$smarty->assign("assetclassgroup", $sth->fetch(PDO::FETCH_OBJ));
|
||||
|
||||
$smarty->display("assetclassgroupedit.tpl");
|
||||
|
||||
|
||||
Reference in New Issue
Block a user