foreach (string str in TestWords)
{
//spam
SqlCommand cmd6 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='" + str + "' and files.spam=1 and folders.id<>" + FolIter + " and files.folderid<>" + FolIter + " and files.id='" + s[0].ToString + "'", cn);
int i6 = Convert.ToInt16(cmd6.ExecuteScalar());
double temp = Convert.ToDouble((i6 + 1) / (i7 + i8));
//non spam
**error**
SqlCommand cmd9 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='"
+ str
+ "' and files.spam=0 and folders.id<>"
+ FolIter
+ " and files.folderid<>"
+ FolIter
+ " and files.id='"
+ s[0].ToString
+ "'", cn);
int i9 = Convert.ToInt16(cmd9.ExecuteScalar());
temp2 = Convert.ToDouble((i9 + 1) / (i7 + i8));
Sdoc = Convert.ToDouble(Sdoc * temp);
NsDoc = Convert.ToDouble(NsDoc * temp2);
}
Run Code Online (Sandbox Code Playgroud)
我得到的错误是:运算符'+'不能应用于'string'和'method group'类型的操作数
正如Nix,Femaref和Azhar所提到的,.ToString()是触发错误消息的错字.
我可以建议使用参数而不是字符串连接吗?这条路:
SqlCommand cmd9 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname=@name and and files.spam=0 and folders.id<>@FolIter and files.folderid<>@FolIter and files.id=@s0", cn);
cmd9.Parameters.Add(new SqlParameter("@name", str));
cmd9.Parameters.Add(new SqlParameter("@FolIter", FolIter));
cmd9.Parameters.Add(new SqlParameter("s0", s0));
Run Code Online (Sandbox Code Playgroud)
通过这种方式,ADO.NET将按原样处理您的变量,您不必将它们转换为字符串以使用连接,并且您不会暴露于SQL注入风险.
| 归档时间: |
|
| 查看次数: |
408 次 |
| 最近记录: |