Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

sql×¢Èë

Ê×ÏÈÎÒÏëлл԰×ÓµÄÅóÓÑÃÇ£¬ÊÇÄãÃÇÌáÐÑÎÒдÄÚÈÝÓдíÎ󣬼ǵÃÔø¾­µç×ÓÉÌÎñÖ®Êý¾Ý´æ´¢Á÷³Ì£¨Î壩ÀïÃæËµµ½“Ñ¡´æ´¢¹ý³Ì+´«µÝ²ÎÊýÓÃSqlParameterÊÇÒòΪ£¬³ý·ÇÊÇADO.NETÓЩ¶´£¬ÄÇô¾Í¾ø¶Ô²»»á·¢ÉúSQL×¢È딡£Keep Walking´ó¸çÒ²ÔÚ¹ØÓÚ·ÀÖ¹sql×¢ÈëµÄ¼¸ÖÖÊֶΣ¨¶þ£©ÖоٳöÀ´Ò»¸öÀý×Ó˵Ã÷ÎÒ˵µÄÉϾ仰ÊÇ´íÎóµÄ¡£ËµÊµ»°µ±Ê±ÎÒ»¹ÊǶÔSQL×¢Èë²»ÊǺÜÁ˽⣬ҲûÓÐÓöµ½¹ýSQL×¢È룬Ҳ²»ÊǺܹØÐÄËü¡£µ«ÊÇÎÒÏ밲ȫµÄÎÊÌâÎÒÃÇÒ»¶¨Òª·Ç³£×¢Ò⣬ÓÚÊÇÕâЩʱºò»¨ÁËһЩʱ¼äÀ´Ñ§Ï°ÁËSQL×¢Èë¡£
ʲôÊÇSQL×¢Èë
¡¡¡¡¿ÉÄÜ´ó¼Ò»¹²»ÊǶÔSQL×¢ÈëÕâ¸ö¸ÅÄî²»ÊǺÜÇå³þ£¬¼òµ¥µØËµ,SQL×¢Èë¾ÍÊǹ¥»÷Õßͨ¹ýÕý³£µÄWEBÒ³Ãæ,°Ñ×Ô¼ºSQL´úÂë´«Èëµ½Ó¦ÓóÌÐòÖÐ,´Ó¶øÍ¨¹ýÖ´ÐзdzÌÐòÔ±Ô¤ÆÚµÄSQL´úÂë,´ïµ½ÇÔÈ¡Êý¾Ý»òÆÆ»µµÄÄ¿µÄ¡£
¡¡¡¡µ±Ó¦ÓóÌÐòʹÓÃÊäÈëÄÚÈÝÀ´¹¹Ô춯̬SQLÓï¾äÒÔ·ÃÎÊÊý¾Ý¿âʱ£¬»á·¢ÉúSQL×¢Èë¹¥»÷¡£Èç¹û´úÂëʹÓô洢¹ý³Ì£¬¶øÕâЩ´æ´¢¹ý³Ì×÷Ϊ°üº¬Î´É¸Ñ¡µÄÓû§ÊäÈëµÄ×Ö·û´®À´´«µÝ£¬Ò²»á·¢ÉúSQL×¢Èë¡£SQL×¢Èë¿ÉÄܵ¼Ö¹¥»÷ÕßʹÓÃÓ¦ÓóÌÐòµÇ½ÔÚÊý¾Ý¿âÖÐÖ´ÐÐÃüÁî¡£Èç¹ûÓ¦ÓóÌÐòʹÓÃÌØÈ¨¹ý¸ßµÄÕÊ»§Á¬½Óµ½Êý¾Ý¿â£¬ÕâÖÖÎÊÌâ»á±äµÃºÜÑÏÖØ¡£ÔÚijЩ±íµ¥ÖУ¬Óû§ÊäÈëµÄÄÚÈÝÖ±½ÓÓÃÀ´¹¹Ô죨»òÕßÓ°Ï죩¶¯Ì¬SQLÃüÁ»òÕß×÷Ϊ´æ´¢¹ý³ÌµÄÊäÈë²ÎÊý£¬ÕâЩ±íµ¥ÌرðÈÝÒ×Êܵ½SQL×¢ÈëµÄ¹¥»÷¡£¶øÐí¶àÍøÕ¾³ÌÐòÔÚ±àдʱ£¬Ã»ÓжÔÓû§ÊäÈëµÄºÏ·¨ÐÔ½øÐÐÅжϻòÕß³ÌÐòÖб¾ÉíµÄ±äÁ¿´¦Àí²»µ±£¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£ÕâÑù£¬Óû§¾Í¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯµÄ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃһЩÃô¸ÐµÄÐÅÏ¢»òÕß¿ØÖÆÕû¸ö·þÎñÆ÷£¬ÓÚÊÇSQL×¢Èë¾Í·¢ÉúÁË¡£
Ò»°ãSQL×¢Èë
¡¡¡¡ÔÚWeb Ó¦ÓóÌÐòµÄµÇ¼ÑéÖ¤³ÌÐòÖÐ,Ò»°ãÓÐÓû§Ãû(username) ºÍÃÜÂë(password) Á½¸ö²ÎÊý,³ÌÐò»áͨ¹ýÓû§ËùÌá½»ÊäÈëµÄÓû§ÃûºÍÃÜÂëÀ´Ö´ÐÐÊÚȨ²Ù×÷¡£ÎÒÃÇÓкܶàÈËϲ»¶½«SQLÓï¾äÆ´½ÓÆðÀ´¡£ÀýÈ磺
¡¡¡¡Select * from users where username =’ txtusername.Text ’ and  password =’ txtpassword.Text ’
¡¡¡¡ÆäÔ­ÀíÊÇͨ¹ý²éÕÒusers ±íÖеÄÓû§Ãû(username) ºÍÃÜÂë(password) µÄ½á¹ûÀ´½øÐÐÊÚȨ·ÃÎÊ, ÔÚtxtusername.TextΪmysql£¬txtpassword.TextΪmary£¬ÄÇôSQL²éѯÓï¾ä¾ÍΪ£º
¡¡¡¡Select * from users where username =’ mysql ’ and  password  =’ mary ’
¡¡¡¡Èç¹û·Ö±ð¸øtxtusername.Text ºÍtxtpassword.Text¸³Öµ’ or ‘1’ = ‘1’ --ºÍab


Ïà¹ØÎĵµ£º

SQL ¸ßЧͨÓ÷ÖÒ³´æ´¢¹ý³Ì(Ë«Ïò¼ìË÷)

create PROC [dbo].[P_viewPage_A]
/*
¸ßЧͨÓ÷ÖÒ³´æ´¢¹ý³Ì(Ë«Ïò¼ìË÷)
¾´¸æ£ºÊÊÓÃÓÚµ¥Ò»Ö÷¼ü»ò´æÔÚΨһֵÁеıí»òÊÓͼ
ps:SqlÓï¾äΪ8000×Ö½Ú,µ÷ÓÃʱÇë×¢Òâ´«Èë²ÎÊý¼°sql×ܳ¤¶È²»Òª³¬¹ýÖ¸¶¨·¶Î§
*/
@TableName VARCHAR(200),     --±íÃû
@FieldList VARCHAR(2000),    --ÏÔʾÁÐà ......

sql server ´æ´¢¹ý³ÌÀïµÄlikeº¯Êý¡£

    ÒÔstring ÀàÐ͵ÄNameΪÀý
ÔÚSQL Óï¾äÀ string sql="Name like'%" + Name.Text + "%';
ÔÚ´æ´¢¹ý³ÌÀ
    if @Name!=''
begin
 set @strWhere= +'  and Name like '''+'%'+@Name+'%'+''''
end
´æ´¢¹ý³ÌÖеÄÒýºÅÊǵ¥ÒýºÅ.
like '''+'%'Öм䲻ÓÃ+Èϲ» ......

ADO.NETÖеÄsqlÁ¬½Ó

using System.Data;            // Use ADO.NET namespace
using System.Data.SqlClient;  
 SqlConnection thisConnection = new SqlConnection(
      &nbs ......

²¶»ñSqlÒì³£

°ïÖúÀïµÄ,Óï·¨:
BEGIN TRY
    { sql_statement | statement_block }
END TRY
BEGIN CATCH
          [ { sql_statement | statement_block } ]
END CATCH
[ ; ]
Òì³£²¿·Ö:
ÔÚ CATCH ¿éµÄ×÷ÓÃÓòÄÚ£¬¿ÉÒÔʹÓÃÒÔÏÂϵͳº¯ÊýÀ´»ñÈ¡µ¼Ö CATCH ¿éÖ´ÐеĴíÎóÏûÏ¢£º
ERROR ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ