iBatis杂记

queryForObject()
queryForList()
queryForMap()

Mapped statement types
select
insert
update
delete
procedure
statement
sql
include


sql:
select ... where city like '%$values$%'
this form is easy sql injection



posted @ 2011-06-13 23:31  庚武  Views(163)  Comments(0Edit  收藏  举报