diff --git a/include/ajax.tickets.php b/include/ajax.tickets.php index 376e2a41d7ed76d4ff9e27b485dc1a121930e8b6..9d5169dbd56020c34b3374c90d4fb1ac77a63a47 100644 --- a/include/ajax.tickets.php +++ b/include/ajax.tickets.php @@ -211,11 +211,11 @@ class TicketsAjaxAPI extends AjaxController { foreach (TicketForm::getInstance()->getFields() as $f) { if (isset($req[$f->getFormName()]) && ($val = $req[$f->getFormName()])) { - $name = $f->get('name') ? db_real_escape($f->get('name')) + $name = $f->get('name') ? $f->get('name') : 'field_'.$f->get('id'); - $cwhere = "cdata.\"$name\" LIKE '%".db_real_escape($val)."%'"; + $cwhere = "cdata.`$name` LIKE '%".db_real_escape($val)."%'"; if ($f->getImpl()->hasIdValue() && is_numeric($val)) - $cwhere .= " OR cdata.\"{$name}_id\" = ".db_input($val); + $cwhere .= " OR cdata.`{$name}_id` = ".db_input($val); $where .= ' AND ('.$cwhere.')'; $cdata_search = true; }