2021-04-20 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdvairplayd/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdvairplayd/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason 2021-04-20 08:43:15 -04:00
parent 6b4050c3e8
commit efd3920bb5
2 changed files with 6 additions and 2 deletions

View File

@ -21535,3 +21535,7 @@
* Escaped all SQL identifiers in 'rdservice/'.
* Replaced " with ' delimiters in all SQL literal strings in
'rdservice/'.
2021-04-20 Fred Gleason <fredg@paravelsystems.com>
* Escaped all SQL identifiers in 'rdvairplayd/'.
* Replaced " with ' delimiters in all SQL literal strings in
'rdvairplayd/'.

View File

@ -229,8 +229,8 @@ void MainObject::ripcConnectedData(bool state)
break;
}
if(!air_start_lognames[i].isEmpty()) {
sql=QString("select NAME from LOGS where ")+
"NAME=\""+RDEscapeString(air_start_lognames[i])+"\"";
sql=QString("select `NAME` from `LOGS` where ")+
"`NAME`='"+RDEscapeString(air_start_lognames[i])+"'";
q=new RDSqlQuery(sql);
if(q->first()) {
rml.clear();