学无止境详情

使用参数化SQL语句进行模糊查找

发表:2017-01-19    编辑:南昌开优网络    浏览:4952    
标签:SQL使用

1、使用参数化SQL语句进行模糊查找的正确方法:

//定义sql语句

string sql = "SELECT StudentID,StudentNO,StudentName FROM Student WHERE StudentName like @StudentName";

//给参数赋值

command.Parameters.AddWithValue("@StudentName", txtStudentName.Text+"%");

 

2.错误做法1:

//定义sql语句

string sql = "SELECT StudentID,StudentNO,StudentName FROM Student WHERE StudentName like '@StudentName%'";

//给参数赋值

command.Parameters.AddWithValue("@StudentName", txtStudentName.Text); 

 

3.错误做法2: 

//定义sql语句 

string sql = "SELECT StudentID,StudentNO,StudentName FROM Student WHERE StudentName like @StudentName%"; 

//给参数赋值 

command.Parameters.AddWithValue("@StudentName", txtStudentName.Text);



分享
  1. 上一篇:access2007\access201...
  2. 下一篇:SQL中Between语句查询日期