diff --git a/include/client/tickets.inc.php b/include/client/tickets.inc.php index 2adfa33e2d25202ee24d2534914091a21a524d01..3665c8a3134da4786c2d352186384e8ad96587c5 100644 --- a/include/client/tickets.inc.php +++ b/include/client/tickets.inc.php @@ -70,10 +70,10 @@ if($status && isset($states[$status])){ $search=($_REQUEST['a']=='search' && $_REQUEST['q']); if($search) { $qs += array('a' => $_REQUEST['a'], 'q' => $_REQUEST['q']); + $queryterm=db_real_escape($_REQUEST['q'],false); //escape the term ONLY...no quotes. if(is_numeric($_REQUEST['q'])) { $qwhere.=" AND ticket.`number` LIKE '$queryterm%'"; } else {//Deep search! - $queryterm=db_real_escape($_REQUEST['q'],false); //escape the term ONLY...no quotes. $qwhere.=' AND ( ' ." cdata.subject LIKE '%$queryterm%'" ." OR thread.body LIKE '%$queryterm%'"