Quantcast
Channel: ฟอรัม Getting started with SQL Server
Viewing all articles
Browse latest Browse all 8428

How can I write this query In parameterize form so That I can prevent sql Injection

$
0
0
String strQry ="INSERT INTO tblVoucherType (VhrTypeCode,moduleCode,transCCode,"+"voucherType,OrderNumber,active,AccountId) "+" values('"+ txtVhrCode.Text+"','"+ ddlModule.SelectedValue.ToString()+"',"+"'"+ ddlTrans.SelectedValue.ToString()+"','"+ txtVhrName.Text+"','"+ btnRadio.SelectedValue+"'"+", '"+ status.Checked+"', '"+ txtAccount.Text+"')";

Viewing all articles
Browse latest Browse all 8428

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>