Just trying to make sure all my queries are sanitized. We're using ADOdb (it's already in place, so no talking me out of it).
Is there something in ADOdb like mysql_real_esca开发者_C百科pe_string?
Use parameterized queries.
MySqlCommand cmd = new MySqlCommand();
string usernName = ...;
cmd.CommandText = "select userid,age from Users where username=@username)"
cmd.Parameters.AddWithValue("@username", userName);;
MySqlDataReader reader = smd.ExecuteReader();
精彩评论