prepare(?) & execute($var) modif
authortipaul <tipaul>
Fri, 28 Nov 2003 14:06:57 +0000 (14:06 +0000)
committertipaul <tipaul>
Fri, 28 Nov 2003 14:06:57 +0000 (14:06 +0000)
C4/Input.pm

index 1bf1ea6..528f680 100644 (file)
@@ -93,9 +93,9 @@ sub checkdigit {
        unless ( $nounique )
        {
                my $dbh=C4::Context->dbh;
-               my $query=qq{SELECT * FROM borrowers WHERE cardnumber="$infl"};
+               my $query=qq{SELECT * FROM borrowers WHERE cardnumber=?};
                my $sth=$dbh->prepare($query);
-               $sth->execute;
+               $sth->execute($infl);
                my %results = $sth->fetchrow_hashref();
                if ( $sth->rows != 0 )
                {