2021-04-20 Fred Gleason <fredg@paravelsystems.com>

* Escaped all SQL identifiers in 'rdvairplayd/'.
	* Replaced " with ' delimiters in all SQL literal strings in
	'rdvairplayd/'.

Signed-off-by: Fred Gleason <fredg@paravelsystems.com>
This commit is contained in:
Fred Gleason
2021-04-20 08:43:15 -04:00
parent 6b4050c3e8
commit efd3920bb5
2 changed files with 6 additions and 2 deletions

View File

@@ -229,8 +229,8 @@ void MainObject::ripcConnectedData(bool state)
break;
}
if(!air_start_lognames[i].isEmpty()) {
sql=QString("select NAME from LOGS where ")+
"NAME=\""+RDEscapeString(air_start_lognames[i])+"\"";
sql=QString("select `NAME` from `LOGS` where ")+
"`NAME`='"+RDEscapeString(air_start_lognames[i])+"'";
q=new RDSqlQuery(sql);
if(q->first()) {
rml.clear();