开发者

ADOdb sanitizing queries

Just trying to make sure all my queries are sanitized. We're using ADOdb (it's already in place, so no talking me out of it).

Is there something in ADOdb like mysql_real_esca开发者_C百科pe_string?


Use parameterized queries.

MySqlCommand cmd = new MySqlCommand();
string usernName = ...;
cmd.CommandText = "select userid,age from Users where username=@username)"
cmd.Parameters.AddWithValue("@username", userName);;
MySqlDataReader reader =  smd.ExecuteReader();
0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜