src/strip.vala
authorAlan Knowles <alan@roojs.com>
Fri, 4 May 2018 05:18:19 +0000 (13:18 +0800)
committerAlan Knowles <alan@roojs.com>
Fri, 4 May 2018 05:18:19 +0000 (13:18 +0800)
src/strip.vala

index 66ee319..c0b86ae 100644 (file)
@@ -422,7 +422,11 @@ public class Strip : GLib.Object {
                                '%s', -- in_mime_filename varchar(255)
                                %d -- filesize
                        ) as id ;
-          """.printf( chksum, file_size)
+          """.printf(
+                       this.mysql_escape(this.active_message_exim_id),
+                       chksum,
+                       this.mysql_escape( attachment.get_filename() ), // what is thsi is invalid?
+                        file_size)
                );
                var file_id = "0";
         var rs = mysql.use_result();