class SqlHelper { SqlDataReader SqlDataReader ExecuteRead(string s,params SqlParameter[] ps) { string str = Configuration.ConnectionStrings[“str”].ConnectionString using(SqlConnection conn = new SqlConnection(connStr)) { using(SqlCommand cmd = conn.CreateCommand()) { cmd.CommandText = sql; foreach(SqlParaneter param in parameters) { cmd.Parameters.Add(param); } return cmd.ExucuteReader(); } } } }
using(SqlCommand cmd = conn.CreateCommand()) { cmd.CommandText = “insert t_users(username,password)values(‘admin’,’888888’)”; cmd.ExecuteNonQuery(); }
例: 获得自动增长字段主键值(() output inserted.*(主键值) values())
例: ①按照用户提供的用户名/密码插入数据库 ②用户名登陆练习 ③输出数据库数据条目数 ④输出员工表姓名列abcdefghijk…
例: 注入漏洞与参数化查询 cmd.CommandText = "select count(*) from t_employee where name=@userName and password=@passWord+"; cmd.Parameters.Add(new SqlParameter("userName",userName)); cmd.Parameters.Add(new SqlParameter(“passWord”,passWord));
|





骆驼户外男 真皮磨砂日常休闲鞋 低帮 2011秋冬新款 专柜正品特价