c#Sqlcommand错误

use*_*640 1 .net c#

foreach (string str in TestWords)
{
  //spam
  SqlCommand cmd6 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='" + str + "' and files.spam=1 and folders.id<>" + FolIter + " and files.folderid<>" + FolIter + " and files.id='" + s[0].ToString + "'", cn);
  int i6 = Convert.ToInt16(cmd6.ExecuteScalar());
  double temp = Convert.ToDouble((i6 + 1) / (i7 + i8));
  //non spam

  **error**

  SqlCommand cmd9 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='" 
    + str 
    + "' and files.spam=0 and folders.id<>"
    + FolIter
    + " and files.folderid<>" 
    + FolIter 
    + " and files.id='" 
    + s[0].ToString 
    + "'", cn);
  int i9 = Convert.ToInt16(cmd9.ExecuteScalar());
  temp2 = Convert.ToDouble((i9 + 1) / (i7 + i8));
  Sdoc = Convert.ToDouble(Sdoc * temp);
  NsDoc = Convert.ToDouble(NsDoc * temp2);
}
Run Code Online (Sandbox Code Playgroud)

我得到的错误是:运算符'+'不能应用于'string'和'method group'类型的操作数

Fem*_*ref 9

你必须调用方法:

s[0].ToString()
Run Code Online (Sandbox Code Playgroud)


Lar*_*rry 7

正如Nix,Femaref和Azhar所提到的,.ToString()是触发错误消息的错字.

我可以建议使用参数而不是字符串连接吗?这条路:

SqlCommand cmd9 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname=@name and and files.spam=0 and folders.id<>@FolIter and files.folderid<>@FolIter and files.id=@s0", cn);

cmd9.Parameters.Add(new SqlParameter("@name", str));
cmd9.Parameters.Add(new SqlParameter("@FolIter", FolIter));
cmd9.Parameters.Add(new SqlParameter("s0", s0));
Run Code Online (Sandbox Code Playgroud)

通过这种方式,ADO.NET将按原样处理您的变量,您不必将它们转换为字符串以使用连接,并且您不会暴露于SQL注入风险.