1、SQL语句带参数的
(1)、
public static int Updata(string sql)
{
SqlConnection conn = new SqlConnection(connString);
SqlCommand cmd = new SqlCommand(sql, conn);
try
{
conn.Open();
return cmd.ExecuteNonQuery();
}
catch (Exception ex)
{
throw ex;
}
finally
{
conn.Close();
}
}
(2)
public static int Updata(string sql,,SqlParameter[] param)
{
SqlConnection conn = new SqlConnection(connString);
SqlCommand cmd = new SqlCommand(sql, conn);
try
{
conn.Open();
cmd.Parameters.AddRange(param)
return cmd.ExecuteNonQuery();
}
catch (Exception ex)
{
throw ex;
}
finally
{
conn.Close();
}
}
3:SQL语言
string sql=“Select LoginId,LoginPWD from Admin Where LoginId=@LoginId and LoginPWD=@LogindPWD”;
SqlParameter[] parameter= new SqlParameter[]
{
new SqlParameter("@LoginId",objAdmin.LoginId),
new SqlParameter("@LoginPWD",objAdmin.LoginPWD),
}