|
楼主 |
发表于 2020-4-4 16:45:01
|
显示全部楼层
还是不行啊,我是这样写的
OleDbConnection con = new OleDbConnection ("server=hp;uid=sa;pwd=sa;database=test;Provider=SQLOLEDB");
string sql = "select * from members where userName=@userName";
OleDbCommand cmd = new OleDbCommand(sql, con);
con.Open();
//防止注入式攻击
cmd.Parameters.Add("@userName", OleDbType.VarChar, 50);
cmd.Parameters["@userName"].Value = this.TextBox1.Text.Replace("'", "");
sql的值还是select * from members where userName=@userName
哪里错了?急啊~ |
|