【发布时间】:2016-12-13 21:13:03
【问题描述】:
我遇到了一个错误
System.Data.dll 中出现“System.Data.SqlClient.SqlException”类型的异常,但未在用户代码中处理
附加信息:关键字“用户”附近的语法不正确。
我的代码:
SqlConnection con = new SqlConnection(@"Data Source = (LocalDB)\MSSQLLocalDB; AttachDbFilename = C:\Users\user\OneDrive\Documents\Visual Studio 2015\Projects\WebApplication2\WebApplication2\App_Data\Database1.mdf; Integrated Security = True");
protected void btnOK_Click(object sender, EventArgs e)
{
con.Open();
SqlCommand cmd = con.CreateCommand();
cmd.CommandType = CommandType.Text;
cmd.CommandText = "insert into User(name, status, type) values('"+txtName.Text+"', '"+txtStatus.Text+ "', '" + txtType.Text + "')";
cmd.ExecuteNonQuery();
con.Close();
Response.Redirect("Webform1.aspx");
}
【问题讨论】:
-
在开始编写将 button_click 事件与 SqlCommand 对象混合的代码之前,请先阅读此内容。 msdn.microsoft.com/en-us/library/…
-
SQL Injection alert - 你应该不将你的 SQL 语句连接在一起 - 使用 参数化查询 来避免 SQL 注入
标签: c# asp.net sql-server