C# SQL防注入

string sql = "select * from student where id like" +"@key";
Sqlconnection con = new Sqlconnetion();
Sqlcommand com =new Sqlcommand();
SqlParameter prmid = new SqlParameter();
prmid.ParameterName = "@key";
prmid.Value=key;
com.Parameters.Add(prmid);

 

posted @ 2017-09-06 11:31  水泽  阅读(1012)  评论(0编辑  收藏  举报