且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

将包含特殊字符'的字符串插入sql db

更新时间:2023-02-26 10:54:36

您应该使用SqlParameter. http://msdn.microsoft.com/en-us/library/yy6y35y8.aspx

You should be using SqlParameter. http://msdn.microsoft.com/en-us/library/yy6y35y8.aspx

    string query = "insert into ACTIVE.dbo.Workspaces_WsToRefile values(@folderID, @newWorkSpace, @createDate)";

using(SqlCommand cmd = new SqlCommand(query, SqlConnection))
{

    SqlParameter param = new SqlParameter("@folderID", folderId);
    param.SqlDbType = SqlDbType.Int;
    cmd.Parameters.Add(param);
    .....
}