·Parameters带参数SQL语句,这样可以防止SQL注入
String MySelectQuery = "select * from [yl_organization] where organization_pname=@user_pname and organization_pwd=@user_wpwd and organization_state=0 and yaolee_del=0";
SqlCommand MyCommand = new SqlCommand(MySelectQuery, MyConnection);
SqlParameter param0 = new SqlParameter("@user_pname", SqlDbType.VarChar, 50);
param0.Value = uname.Text;
MyCommand.Parameters.Add(param0);
SqlParameter param1 = new SqlParameter("@user_wpwd", SqlDbType.VarChar, 50);
param1.Value = MD5(pwd.Text);
//param1.Value=pwd.Text;
MyCommand.Parameters.Add(param1);

被折叠的 条评论
为什么被折叠?



