diff --git a/accounts.php b/accounts.php index 6bf648fb..3d44cb85 100644 --- a/accounts.php +++ b/accounts.php @@ -15,13 +15,13 @@ } if(isset($_GET['q'])){ - $q = $_GET['q']; + $q = mysqli_real_escape_string($mysqli,$_GET['q']); }else{ $q = ""; } if(!empty($_GET['sb'])){ - $sb = $_GET['sb']; + $sb = mysqli_real_escape_string($mysqli,$_GET['sb']); }else{ $sb = "account_id"; } @@ -57,7 +57,7 @@