java代码中的涉及sql语句需注意的事项:
字符串的加入要额外加引号
正确:
String sql = "SELECT count(*) from user where name=\"" + name + "\" and password=\"" + password + "\"";
错误:
String sql = "SELECT count(*) from user where name=" + name + " and password=" + password;
字符串 " " 中加引号用 \" (或者用/")