工作文档

来源:互联网 发布:印度人怎么看中国知乎 编辑:程序博客网 时间:2024/04/27 17:13

 ·Parameters带参数SQL语句,这样可以防止SQL注入

String MySelectQuery = "select * from [yl_organization] where organization_pname=@user_pname and organization_pwd=@user_wpwd and organization_state=0 and yaolee_del=0";
SqlCommand MyCommand = new SqlCommand(MySelectQuery, MyConnection);

 SqlParameter param0 = new SqlParameter("@user_pname", SqlDbType.VarChar, 50);
param0.Value = uname.Text;
MyCommand.Parameters.Add(param0);
SqlParameter param1 = new SqlParameter("@user_wpwd", SqlDbType.VarChar, 50);
param1.Value = MD5(pwd.Text);
//param1.Value=pwd.Text;
MyCommand.Parameters.Add(param1);

原创粉丝点击