开发者

Deleting records from a table, is this correct?

I want to delete some record from table ,by running this Query in C# is it Correct or not,

Please help me

开发者_C百科SqlCommand cmdRe = new SqlCommand("insert into msisdn_master SELECT *  from tblDeactive
where msisdn in (" + str_MSISDN + ")", cn);
SqlCommand cmdRed = new SqlCommand("delete from tblDeactive where msisdn in ("+str_MSISDN+")", cn);
cmdRe.CommandType = CommandType.Text;
cmdRed.CommandType = CommandType.Text;

note : str_MSISDN is the StringBuilder which stores the Number which is inserted in TextField.


You should be using proper SQL parameters. NEVER use string building since that leaves you open for injection attacks.

Read this tutorial to learn how to add parameters to SqlCommands.

0

上一篇:

下一篇:

精彩评论

暂无评论...
验证码 换一张
取 消

最新问答

问答排行榜