参数化SQL语句一定程度上防止SQL注入

it2022-05-05  138

  public bool InsertAdmin(string userName, string password, string remark, string mail, int departId, int power)ÆïǾLâ½íwww.netcsharp.cnQfòç=û\    {        string sql = "insert into S_Admin(UserName,Password,Remark,Mail,DepartId,Power)values(@UserName,@Password,@Remark,@Mail,@DepartId,@Power)";        SqlConnection connection = new SqlConnection();        connection.ConnectionString = "";//此处设置链接字符串        SqlCommand command = new SqlCommand(sql, connection);        command.Parameters.Add("@UserName",SqlDbType.NVarChar, 60).Value = userName;       

        command.Parameters.Add("@Password", SqlDbType.NVarChar, 60).Value = password;        command.Parameters.Add("@Remark", SqlDbType.NVarChar, 60).Value = remark;        command.Parameters.Add("@Mail", SqlDbType.NVarChar, 60).Value = mail;       

        command.Parameters.Add("@DepartId", SqlDbType.Int, 4).Value = departId;        command.Parameters.Add("@Power", SqlDbType.Int, 4).Value = power;     

        connection.Open();        int rowsAffected = command.ExecuteNonQuery();        connection.Close();        command.Dispose();        return rowsAffected > 0;    }}

转载于:https://www.cnblogs.com/renjuwht/archive/2009/07/17/1525930.html


最新回复(0)