万恶的SQL注入漏洞

来源:互联网 发布:免费房产中介软件 编辑:程序博客网 时间:2024/06/06 01:49


           string strConn = "DataSource=Fanbin-VAIO;Initial Catalog=sales;Integrated Security=True";

          

           Console.WriteLine("请输入用户名");

            stringuserName = Console.ReadLine();

            Console.WriteLine("请输入用户密码");

            stringuserPassword = Console.ReadLine();

            using(SqlConnection conn =newSqlConnection(strConn))

            {

                conn.Open();

                using(SqlCommand cmd = conn.CreateCommand())

                {

                    cmd.CommandText = "select * from t_user where name='" +userName + "'and password='" +userPassword + "'";

                    //cmd.CommandText ="select * from t_user where name=@NM and password=@PW";

                    //cmd.Parameters.Add(newSqlParameter("NM", userName));

                    //cmd.Parameters.Add(newSqlParameter("PW", userPassword));

 

                    SqlDataReaderdr= cmd.ExecuteReader();

                    if(dr.Read())

                    {

                        Console.WriteLine("登陆成功");

                    }

                    else

                    {

                        Console.WriteLine("用户名或密码错误");          

                    }

                }

                Console.ReadLine();

            }

 

原创粉丝点击