zoukankan      html  css  js  c++  java
  • 防止sql注入 参数化解决方案

    StringBuilder strSql=new StringBuilder(); strSql.Append("insert into T_SysLog("); strSql.Append("UserID,UserName,LogContent,CreateTime"); strSql.Append(") values ("); strSql.Append("@UserID,@UserName,@LogContent,@CreateTime");
    strSql.Append(") ");
    strSql.Append(";select @@IDENTITY");
    SqlParameter[] parameters = {
    new SqlParameter("@UserID", SqlDbType.NVarChar,20) ,
    new SqlParameter("@UserName", SqlDbType.NVarChar,50) ,
    new SqlParameter("@LogContent", SqlDbType.Text) , new SqlParameter("@CreateTime", SqlDbType.DateTime)
    };
    parameters[0].Value = model.UserID;
    parameters[1].Value = model.UserName;
    parameters[2].Value = model.LogContent;
    parameters[3].Value = model.CreateTime;

    艾豆社区、豆信框架、豆信开发手册
  • 相关阅读:
    展示
    发布说明
    团队作业Week14
    Scrum Meeting NO.10
    Scrum Meeting NO.9
    Scrum Meeting NO.8
    Scrum Meeting NO.7
    Scrum Meeting NO.6
    ES6/ES2015核心内容
    用React & Webpack构建前端新闻网页
  • 原文地址:https://www.cnblogs.com/zhoumeng780/p/4585138.html
Copyright © 2011-2022 走看看