Commit 950b4da1 authored by Thierry Bugier's avatar Thierry Bugier Committed by Johan Cwiklinski
fix unescaped column name in API

if the column is a reserved word of SQL, the query fails
Signed-off-by: default avatarThierry Bugier <>
......@@ -1265,7 +1265,7 @@ abstract class API extends CommonGLPI {
FROM `$table`
WHERE $where
ORDER BY ".$params['sort']." ".$params['order']."
ORDER BY `".$params['sort']."` ".$params['order']."
LIMIT ".$params['start'].", ".$params['list_limit'];
if ($result = $DB->query($query)) {
while ($data = $DB->fetch_assoc($result)) {
