Rob*_*Rob 40
不要像这样构建SQL语句,它非常不安全(阅读本文).使用参数,即:
var command = new SqlCommand("select * from person where firstname = @firstname");
SqlParameter param = new SqlParameter();
param.ParameterName = "@firstname";
param.Value = "testing12'3";
command.Parameters.Add(param);
Run Code Online (Sandbox Code Playgroud)