参数化查询,ADO.NET 底层将会处理 SQL 注入的问题 (需要SQL SERVER2005)
使用下面的参数化查询
System.Data.SqlClient.SqlConnection cnn = new System.Data.SqlClient.SqlConnection("连接字符串");
System.Data.SqlClient.SqlCommand cm = new System.Data.SqlClient.SqlCommand();
cm.Connection = cnn;
cm.CommandText = "insert into table1 (field1,field2) values(@field1,@field2)";
cm.Parameters.Add("@field1",SqlDbType.Float);
cm.Parameters["@field1"].Value = 1;
cm.Parameters.Add("@field2",SqlDbType.DateTime );
cm.Parameters["@field2"].Value = System.DBNull.Value;
cnn.Open();
cm.ExecuteNonQuery();
cnn.Close();
另一种
我们公司一直用这个函数 去掉特殊字符
public static string CleanString(string inputString)
{
StringBuilder retVal = new StringBuilder();
if ((inputString != null) && (inputString != String.Empty))
{
inputString = inputString.Trim();
for (int i = 0; i < inputString.Length; i++)
{
switch (inputString[i])
{
case '"':
retVal.Append(""");
break;
case '<':
retVal.Append("<");
break;
case '>':
retVal.Append(">");
break;
default:
retVal.Append(inputString[i]);
break;
}
}
retVal.Replace("'", " ");
}
return retVal.ToString();
}
PS:根据petshop改的 呵呵
Trackback: http://tb.blog.csdn.net/TrackBack.aspx?PostId=1464252