=== modified file 'dhis-2/dhis-services/dhis-service-analytics/src/main/java/org/hisp/dhis/analytics/event/data/JdbcEventAnalyticsManager.java' --- dhis-2/dhis-services/dhis-service-analytics/src/main/java/org/hisp/dhis/analytics/event/data/JdbcEventAnalyticsManager.java 2013-12-04 09:25:21 +0000 +++ dhis-2/dhis-services/dhis-service-analytics/src/main/java/org/hisp/dhis/analytics/event/data/JdbcEventAnalyticsManager.java 2013-12-04 13:47:41 +0000 @@ -197,12 +197,12 @@ for ( String item : params.getAsc() ) { - sql += item + " asc,"; + sql += statementBuilder.columnQuote( item ) + " asc,"; } for ( String item : params.getDesc() ) { - sql += item + " desc,"; + sql += statementBuilder.columnQuote( item ) + " desc,"; } sql = removeLast( sql, 1 ) + " "; @@ -380,7 +380,7 @@ { if ( item.hasFilter() ) { - sql += "and lower(" + item.getItem().getUid() + ") " + item.getSqlOperator() + " " + getSqlFilter( item ) + " "; + sql += "and lower(" + statementBuilder.columnQuote( item.getItem().getUid() ) + ") " + item.getSqlOperator() + " " + getSqlFilter( item ) + " "; } } @@ -388,7 +388,7 @@ { if ( filter.hasFilter() ) { - sql += "and lower(" + filter.getItem().getUid() + ") " + filter.getSqlOperator() + " " + getSqlFilter( filter ) + " "; + sql += "and lower(" + statementBuilder.columnQuote( filter.getItem().getUid() ) + ") " + filter.getSqlOperator() + " " + getSqlFilter( filter ) + " "; } }