SQL防注入

来源:互联网 发布:淘宝上买电器可靠吗 编辑:程序博客网 时间:2024/04/25 15:49

方式一:

    string sqlS = "select * from Info WHERE Sequence=@Sequence";            string sqlConStr = @"Data Source = PANLEE-PC\MSSQLSERVER_2; Initial Catalog = ASPNET; Persist Security Info = True; User ID = sa; Password = lipan";            using (SqlConnection sqlCon = new SqlConnection(sqlConStr))            {                sqlCon.Open();                using (SqlCommand sqlCmd = new SqlCommand(sqlS, sqlCon))                {                    sqlCmd.Parameters.Add(new SqlParameter("Sequence", 21));                    var dataReturn = sqlCmd.ExecuteScalar();                }            }


方式二:

    string sqlS = "SELECT * FROM Info WHERE Name=@userName";            SqlParameter[] sqlPara = new SqlParameter[] { new SqlParameter("@userName", SqlDbType.NVarChar, 10) };            sqlPara[0].Value = context.Request.Form["userName"].ToString();            if (SqlHelper.Exists(sqlS, sqlPara))            { return true; }            else { return false; }


0 0
原创粉丝点击