【问题标题】:ASP connection error : Incorrect syntax near the keyword 'UserASP 连接错误:关键字“用户”附近的语法不正确
【发布时间】:2016-12-13 21:13:03
【问题描述】:

我遇到了一个错误

System.Data.dll 中出现“System.Data.SqlClient.SqlException”类型的异常,但未在用户代码中处理

附加信息:关键字“用户”附近的语法不正确。

我的代码:

SqlConnection con = new SqlConnection(@"Data Source = (LocalDB)\MSSQLLocalDB; AttachDbFilename = C:\Users\user\OneDrive\Documents\Visual Studio 2015\Projects\WebApplication2\WebApplication2\App_Data\Database1.mdf; Integrated Security = True");

protected void btnOK_Click(object sender, EventArgs e)
{
    con.Open();

    SqlCommand cmd = con.CreateCommand();
    cmd.CommandType = CommandType.Text;
    cmd.CommandText =  "insert into User(name, status, type) values('"+txtName.Text+"', '"+txtStatus.Text+ "', '" + txtType.Text + "')";

    cmd.ExecuteNonQuery();
    con.Close();
    Response.Redirect("Webform1.aspx");
}

【问题讨论】:

标签: c# asp.net sql-server


【解决方案1】:

User是SQL中的保留关键字,请使用方括号。

试试这个:

 cmd.CommandText =  "insert into [User](name, status, type) values('"+txtName.Text+"', '"+txtStatus.Text+ "', '" + txtType.Text + "')";

【讨论】:

  • 和快乐的sql注入
  • 请不要给出让某人从一开始就在 sql-injection 火车上的答案。 en.wikipedia.org/wiki/SQL_injection
  • 公平地说,OP 从一开始就已经在 sql-injection 列车上。
  • 一些关于未知实例是用户输入类型的可疑假设。坚持手头的问题。
  • 解决方括号的问题可能很简单。让 OP 对充满问题的代码感到满意是一种伤害,而且没有达到本网站答案所期望的水平。
猜你喜欢
  • 1970-01-01
  • 2011-08-30
  • 1970-01-01
  • 1970-01-01
  • 2016-08-23
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多