$sql = "select id,depart_name,first_name,last_name,local_name,extension,mobile,title ";
$sql.= "from pb_extension e, pb_department d ";
$sql.= "where e.depart_id = d.depart_id ";
$sql.= " and d.plant='".$plant."' ";
$sql.= " and (first_name like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= " or last_name like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= " or local_name like '%".htmlentities($HTTP_POST_VARS["q"])."%'";
$sql.= " or extension like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= " or mobile like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= " or depart_name like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= " or title like '%".$HTTP_POST_VARS["q"]."%'";
$sql.= ") ";