mirror of
https://gitlab.archlinux.org/archlinux/aurweb.git
synced 2025-02-03 10:43:03 +01:00
sql wansn't escaped on inserting package sources
This commit is contained in:
parent
a103c7b14c
commit
89d6607684
1 changed files with 1 additions and 1 deletions
|
@ -162,7 +162,7 @@ class PackageDatabase:
|
||||||
# PackageSources
|
# PackageSources
|
||||||
for source in package.sources:
|
for source in package.sources:
|
||||||
q.execute("INSERT INTO PackageSources (PackageID, Source) " +
|
q.execute("INSERT INTO PackageSources (PackageID, Source) " +
|
||||||
"VALUES (" + str(id) + ", '" + source + "')")
|
"VALUES (" + str(id) + ", '" + MySQLdb.escape_string(source) + "')")
|
||||||
# PackageDepends
|
# PackageDepends
|
||||||
for dep in package.depends:
|
for dep in package.depends:
|
||||||
depid = self.lookupOrDummy(dep)
|
depid = self.lookupOrDummy(dep)
|
||||||
|
|
Loading…
Add table
Reference in a new issue