如何将用户提供的输入添加到SQL语句中?
var sql = "INSERT INTO myTable (myField1, myField2) " +
"VALUES ('" + someVariable + "', '" + someTextBox.Text + "');";var cmd = new SqlCommand(sql, myDbConnection);
cmd.ExecuteNonQuery();Dim sql = "INSERT INTO myTable (myField1, myField2) " &
"VALUES ('" & someVariable & "', '" & someTextBox.Text & "');"Dim cmd As New SqlCommand(sql, myDbConnection)
cmd.ExecuteNonQuery()O'Brien),
慕少森
随时随地看视频慕课网APP