AND pm.folderid=" . mysql_real_escape_string($_GET['folderid']) . " ";
AND pm.folderid=" . mysql_real_escape_string($search_folderid) . " ";