Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Database & SysAdmin
  3. Database
  4. Query String

Query String

Scheduled Pinned Locked Moved Database
databasecsharp
2 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C Offline
    C Offline
    cshivaprasad
    wrote on last edited by
    #1

    Can u pls tell me, wether following SQL string format is correct or not. textWord.text,comboCat.text are string variables of C#. indexInCategoryTable and SubCategoryNo are integer variables. "select * from Words where word = N'"+textWord.Text+"' and CategoryTableName = '"+comboCat.Text+"' and IndexInCategoryTable = 'indexInCategoryTable' and SubCategoryNo = 'SubCategoryNo'";

    C 1 Reply Last reply
    0
    • C cshivaprasad

      Can u pls tell me, wether following SQL string format is correct or not. textWord.text,comboCat.text are string variables of C#. indexInCategoryTable and SubCategoryNo are integer variables. "select * from Words where word = N'"+textWord.Text+"' and CategoryTableName = '"+comboCat.Text+"' and IndexInCategoryTable = 'indexInCategoryTable' and SubCategoryNo = 'SubCategoryNo'";

      C Offline
      C Offline
      Colin Angus Mackay
      wrote on last edited by
      #2

      cshivaprasad wrote:

      Can u pls tell me, wether following SQL string format is correct or not

      No. You should use parameters rather than inject values into the query - See SQL Injection Attacks and Tips on How to Prevent Them[^] unless you want your database attacked by a rampaging mob of mallicious attackers.


      "On two occasions, I have been asked [by members of Parliament], 'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able to rightly apprehend the kind of confusion of ideas that could provoke such a question." --Charles Babbage (1791-1871) My: Website | Blog

      1 Reply Last reply
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups