C# winform 防止sql注入代码

来源:互联网 发布:易语言30000源码百度云 编辑:程序博客网 时间:2024/05/29 12:57
string sql = "select count(*) from zhuce where username=@username and pwd=@pwd and type = @type";SqlConnection conn = new SqlConnection(Common.Context.SqlManager.CONN_STRING);            conn.Open();            SqlCommand cmd = new SqlCommand(sql, conn);cmd.Parameters.Add("@username",SqlDbType.VarChar,30);cmd.Parameters.Add("@pwd",SqlDbType.VarChar,30);cmd.Parameters.Add("@type",SqlDbType.VarChar,10);cmd.Parameters["@username"].Value = username;cmd.Parameters["@pwd"].Value = pwd;cmd.Parameters["@type"].Value = power.Text;            int count = Convert.ToInt32(cmd.ExecuteScalar());            conn.Close();
0 0
原创粉丝点击