参数化查询可以防sql注入是因为执行计划重用具体可以看这个博客
https://www.cnblogs.com/qanholas/p/3298890.html
SqlConnection conn = new SqlConnection("连接数据库的字符串");
SqlCommand comm = new SqlCommand("select * from user where user=@user and pass=@password", conn);
SqlParameter parm1 = new SqlParameter("@user", SqlDbType.VarChar, 50); //如果有数字(50),那么这个字段是必须的,缺少会不执行此语句
parm1.Value = user;
SqlParameter parm2 = new SqlParameter("@password", SqlDbType.VarChar);
parm2.Value = password;
comm.Parameters.Add(parm1);
comm.Parameters.Add(parm2);
conn.Open();
object bujidao = comm.ExecuteScalar();
sqlcommand的几个函数
1、查询
comm.ExecuteScalar(); //返回结果集中的第一行第一列,用于查询
2、执行删除,修改
int i = Convert.ToInt32(cmd.ExecuteNonQuery()); //返回Int
3、异步执行增删改查
comm.EndExecuteReader();//并返回sqldatereader
4、sql 参数化 的dbhelper
using System;
using System.Collections.Generic;
using System.Configuration;
using System.Data;
using System.Data.SqlClient;
using System.Linq;
using System.Web;
namespace manager.Models
{
public class SecureDBHelper
{
//这里最好用配置文件
private readonly static string connstr = ConfigurationManager.ConnectionStrings["Conn"].ConnectionString;//这个是连接字符串
/// <summary>
/// 返回受影响的行数
/// </summary>
/// <param name="cmdText">cmd的sql语句</param>
/// <param name="parameter">参数赋值的SqlParameter[]</param>
/// <returns></returns>
public static int ExecuteNonQuery(string cmdText, params SqlParameter[] parameter)
{ //使用using可以自动释放资源
using (SqlConnection conn = new SqlConnection(connstr))
{
conn.Open(); //打开数据库连接
using (SqlCommand cmd = conn.CreateCommand()) //创建连接命令
{
cmd.CommandText = cmdText; //设置连接命令的SQL语句
cmd.Parameters.AddRange(parameter);//参数化使用
return cmd.ExecuteNonQuery(); //返回执行受影响的行数
}
}
}
/// <summary>
/// 返回查询语句的第一行的第一列
/// </summary>
/// <param name="cmdText"></param>
/// <param name="parameter"></param>
/// <returns></returns>
public static object ExecuteScalar(string cmdText, params SqlParameter[] parameter)
{
using (SqlConnection conn = new SqlConnection(connstr))
{
conn.Open();
using (SqlCommand cmd = conn.CreateCommand())
{
cmd.CommandText = cmdText;
cmd.Parameters.AddRange(parameter);
return cmd.ExecuteScalar();
}
}
}
/// <summary>
///
/// </summary>
/// <param name="cmdText"></param>
/// <param name="parameters"></param>
/// <returns>返回datatable</returns>
public static DataTable ExecuteDataTable(string cmdText, params SqlParameter[] parameters)
{
using (SqlConnection conn = new SqlConnection(connstr))
{
conn.Open();
using (SqlCommand cmd = new SqlCommand(cmdText, conn))
{
cmd.Parameters.AddRange(parameters);
using (SqlDataAdapter da = new SqlDataAdapter(cmd))
{
DataTable dt = new DataTable();
da.Fill(dt);
return dt;
}
}
}
}
/// <summary>
///
/// </summary>
/// <param name="cmdText"></param>
/// <param name="parameters"></param>
/// <returns>返回datareader</returns>
public static SqlDataReader ExecuteDataReader(string cmdText, params SqlParameter[] parameters)
{
using (SqlConnection conn = new SqlConnection(connstr))
{
conn.Open();
using (SqlCommand cmd = new SqlCommand(cmdText, conn))
{
cmd.Parameters.AddRange(parameters);
return cmd.ExecuteReader();
}
}
}
/// <summary>
/// 返回dataset
/// </summary>
/// <param name="cmdText"></param>
/// <param name="parameter"></param>
/// <returns></returns>
public static DataSet GetList(string cmdText, params SqlParameter[] parameter)
{
using (SqlConnection conn = new SqlConnection(connstr))
{
conn.Open();
using (SqlCommand cmd = conn.CreateCommand())
{
cmd.CommandText = cmdText;
cmd.Parameters.AddRange(parameter);
using (SqlDataAdapter adapter = new SqlDataAdapter(cmd))
{
DataSet ds = new DataSet();
adapter.Fill(ds);
return ds;
}
}
}
}
}
}
连接字符串在web.config中配置
<connectionStrings>
<add name="Conn" connectionString="Data Source=数据库;Initial Catalog=filemaneger;Persist Security Info=True;User ID=账号;Password=密码" />
</connectionStrings>