sql server - Paramaterized SQL Query C# -
this question has answer here:
this simple query have written. best way paramaterize prevent sql injection?
string selectquery = "select [id] [mydb].[dbo].[mytable] [myname] = '" + user.globalusername + "'";
you can use @
define parameter, this:
string selectquery = "select [id] [mydb].[dbo].[mytable] [myname] = @username;";
then can define parameter using command.parameters
function, this:
cmd.parameters.add("@username", sqldbtype.varchar); cmd.parameters["@username"].value = user.globalusername;
or this:
cmd.parameters.addwithvalue("@username", user.globalusername);
Comments
Post a Comment