Use explicit column name in elec_get_results

This commit is contained in:
Tobias Mueller 2009-06-06 17:43:24 +02:00
parent a9b12101dc
commit ac50b1afb4

View file

@ -209,7 +209,7 @@ function elec_get_results ($handle, $election_id) {
$escaped_election_id = mysql_real_escape_string ($election_id, $handle);
$query = "SELECT * FROM " . $results_table; //FIXME: Don't use wildcards
$query = "SELECT result FROM " . $results_table;
$query .= " WHERE election_id = '".$escaped_election_id."'";
$result = mysql_query ($query, $handle);