database function
-
-
String inputValue;
String sqlText;
SqlConnection connection;
SqlCommand command;
SqlDataReader dataReader;inputValue="123ABC";
sqlText="SELECT dbo.show(" + inputValue +")";
connection=new SqlConnection(" ...whatever your connection stuff is ");try
{
connection.Open();
command=new SqlCommand(sqlText,connection);
SqlDataReader dataReader = command.ExecuteReader();if(dataReader != null)
{
while(dataReader.Read())
{
--get values from dataReader
}
}
}
catch
{}
-
String inputValue;
String sqlText;
SqlConnection connection;
SqlCommand command;
SqlDataReader dataReader;inputValue="123ABC";
sqlText="SELECT dbo.show(" + inputValue +")";
connection=new SqlConnection(" ...whatever your connection stuff is ");try
{
connection.Open();
command=new SqlCommand(sqlText,connection);
SqlDataReader dataReader = command.ExecuteReader();if(dataReader != null)
{
while(dataReader.Read())
{
--get values from dataReader
}
}
}
catch
{}
oooh! shiny! SQL injection, here we come!!!!
Software rusts. Simon Stephenson, ca 1994.
-
oooh! shiny! SQL injection, here we come!!!!
Software rusts. Simon Stephenson, ca 1994.