sql c#
C-#ÈëÞµä(µÚÈý°æ).pdf
using System;
using System.Data;
using System.Data.SqlClient;
namespace My_Student
{
static class Program
{
static void Main()
{
//Á¬½Ó×Ö·û´®£¬Á¬½Ó±¾µØµÄMS SQL Server·þÎñÆ÷
string connString = "data source=MICROSOF-84BB45;persist security info=False;initial catalog=MyDB;integrated security=SSPI;";
//SQLÓï¾ä£¬É¾³ý¼Ç¼
string sqlString = "delete from Courses where CourseNo='001'";
//½¨Á¢Á¬½Ó¶ÔÏó
SqlConnection conn = new SqlConnection(connString);
conn.Open();//´ò¿ªÁ¬½Ó
//½¨Á¢Êý¾ÝÃüÁî¶ÔÏó
SqlCommand cmd = new SqlCommand(sqlString, conn);
//Ö´ÐÐÃüÁ·µ»ØÓ°ÏìµÄÐÐÊý
int rowsReturned = cmd.ExecuteNonQuery();
Console.WriteLine("{0} ¼Ç¼ÒÑɾ³ý", rowsReturned);
MessageBox.Show("Êý¾Ý¿â¸üгɹ¦£¡£¡");
conn.Close();//¹Ø±ÕÁ¬½Ó
}
}
}
try
&nb
Ïà¹ØÎĵµ£º
ϵͳ»·¾³£ºWindows 7
Èí¼þ»·¾³£ºVisual C++ 2008 SP1 +SQL Server 2005
±¾´ÎÄ¿µÄ£º±àдһ¸öº½¿Õ¹ÜÀíϵͳ
ÕâÊÇÊý¾Ý¿â¿Î³ÌÉè¼ÆµÄ³É¹û£¬ËäÈ»³É¼¨²»¼Ñ£¬µ«ÊÇ×÷ΪÎÒÓÃVC++ ÒÔÀ´±àдµÄ×î´ó³ÌÐò»¹ÊÇ´«µ½ÍøÉÏ£¬ÒÔ¹©²Î¿¼¡£ÓÃVC++ ×öÊý¾Ý¿âÉè¼Æ²¢²»ÈÝÒ×£¬µ«Ò²²»ÊDz»¿ÉÄÜ¡£ÒÔÏÂÊÇÎҵijÌÐò½çÃæ£¬ºóÃæ ......
1.²éѯµÄÄ£ºýÆ¥Åä
¾¡Á¿±ÜÃâÔÚÒ»¸ö¸´ÔÓ²éѯÀïÃæÊ¹Óà LIKE '%parm1%'—— ºìÉ«±êʶλÖõİٷֺŻᵼÖÂÏà¹ØÁеÄË÷ÒýÎÞ·¨Ê¹Óã¬×îºÃ²»ÒªÓÃ.
½â¾ö°ì·¨:
ÆäʵֻÐèÒª¶Ô¸Ã½Å±¾ÂÔ×ö¸Ä½ø£¬²éѯËٶȱã»áÌá¸ß½ü°Ù±¶¡£¸Ä½ø·½·¨ÈçÏ£º
a¡¢ÐÞ¸Äǰ̨³ÌÐò——°Ñ²éѯÌõ¼þµÄ¹©Ó¦ÉÌÃû³ÆÒ»À¸ÓÉÔÀ´µÄÎı¾ÊäÈë¸ÄΪÏÂÀÁб ......
1¡¢¼ì²éÊÇ·ñÓзǷ¨×Ö·û
public static boolean sql_inj(String str)
{
String inj_str = "'|and|exec|insert|select|delete|update|
count|*|%|chr|mid|master|truncate|char|declare|;|or|-|+|,";
//ÕâÀïµÄ¶«Î÷»¹¿ÉÒÔ×Ô¼ºÌí¼Ó
String[] inj_stra=inj_str.split("\\|");
for ......
DBHelper:
/// <summary>
/// Ö´Ðвéѯ
/// </summary>
/// <param name="sql">ÓÐЧµÄselectÓï¾ä</param ......
[code]declare @startdt datetime
declare @enddt datetime
select @startdt='2009-12-03',@enddt='2009-12-05'
select * from tb
where ¿ªÊ¼ÈÕÆÚ between @startdt and @enddt
or ½áÊøÈÕÆÚ between @startdt and @enddt
or @startdt between ¿ªÊ¼ÈÕÆÚ and ½áÊøÈÕÆÚ
or @enddt between ¿ªÊ¼ÈÕÆÚ and ......