+ $month_q = $this->db->quote($_GET['month']);
+ $month_sql = " AND DATE_FORMAT(item_valid_from, '%Y-%m') = ".$month_q;
+ $month_sql_bought = " AND DATE_FORMAT(item_date_bought, '%Y-%m') = ".$month_q;
+ $month_sql_sold = " AND DATE_FORMAT(item_date_sold, '%Y-%m') = ".$month_q;