sql server - Paramaterized SQL Query C# -


this question has answer here:

this simple query have written. best way paramaterize prevent sql injection?

string selectquery = "select [id] [mydb].[dbo].[mytable] [myname] = '" +  user.globalusername + "'"; 

you can use @ define parameter, this:

string selectquery = "select [id] [mydb].[dbo].[mytable] [myname] = @username;"; 

then can define parameter using command.parameters function, this:

cmd.parameters.add("@username", sqldbtype.varchar); cmd.parameters["@username"].value = user.globalusername; 

or this:

cmd.parameters.addwithvalue("@username", user.globalusername); 

Comments

Popular posts from this blog

python - TypeError: start must be a integer -

c# - DevExpress RepositoryItemComboBox BackColor property ignored -

django - Creating multiple model instances in DRF3 -