Click here to Skip to main content
15,898,035 members
Home / Discussions / C#
   

C#

 
GeneralRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 8:13
Colin Angus Mackay7-Jun-06 8:13 
AnswerRe: C#/SQL Question Pin
Gerald Schwab7-Jun-06 6:53
Gerald Schwab7-Jun-06 6:53 
GeneralRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 8:14
Colin Angus Mackay7-Jun-06 8:14 
GeneralRe: C#/SQL Question Pin
Gerald Schwab9-Jun-06 7:07
Gerald Schwab9-Jun-06 7:07 
GeneralRe: C#/SQL Question Pin
Colin Angus Mackay9-Jun-06 11:20
Colin Angus Mackay9-Jun-06 11:20 
AnswerRe: C#/SQL Question Pin
malikjhangirahmed@hotmail.com7-Jun-06 7:21
malikjhangirahmed@hotmail.com7-Jun-06 7:21 
GeneralRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 8:14
Colin Angus Mackay7-Jun-06 8:14 
AnswerRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 8:11
Colin Angus Mackay7-Jun-06 8:11 
All of your replies, disappointingly, contain a major security flaw. You should never inject values into a SQL string when you can use a parameter instead. For more information see SQL Injection Attacks and Tips on How to Prevent Them[^]

You may want to re-write your code to resemble this:
string SQLString = "SELECT * FROM Costs WHERE Costs.PartID = @PartID";
SqlCommand cmd = new SqlCommand();
cmd.Connection = myConnection;
cmd.CommandText = SQLString;
cmd.Parameters.Add("@PartID", strPartNumberInput);


If Costs.PartID is an int column then you'll have to convert the strPartNumberInput into an integer first: Convert.ToInt32(strPaetNumberInput)

Does this help?


"On two occasions, I have been asked [by members of Parliament], 'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able to rightly apprehend the kind of confusion of ideas that could provoke such a question."
--Charles Babbage (1791-1871)

My: Website | Blog
QuestionRe: C#/SQL Question Pin
leckey7-Jun-06 8:15
leckey7-Jun-06 8:15 
AnswerRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 8:29
Colin Angus Mackay7-Jun-06 8:29 
GeneralRe: C#/SQL Question Pin
leckey7-Jun-06 8:36
leckey7-Jun-06 8:36 
GeneralRe: C#/SQL Question Pin
leckey7-Jun-06 8:55
leckey7-Jun-06 8:55 
GeneralRe: C#/SQL Question Pin
Josh Smith7-Jun-06 9:01
Josh Smith7-Jun-06 9:01 
GeneralRe: C#/SQL Question Pin
Colin Angus Mackay7-Jun-06 9:03
Colin Angus Mackay7-Jun-06 9:03 
GeneralRe: C#/SQL Question Pin
leckey7-Jun-06 9:16
leckey7-Jun-06 9:16 
GeneralRe: C#/SQL Question Pin
Josh Smith7-Jun-06 9:29
Josh Smith7-Jun-06 9:29 
GeneralRe: C#/SQL Question Pin
leckey7-Jun-06 9:31
leckey7-Jun-06 9:31 
GeneralRe: C#/SQL Question [modified] Pin
Josh Smith7-Jun-06 9:38
Josh Smith7-Jun-06 9:38 
GeneralRe: C#/SQL Question--New Problem Pin
leckey7-Jun-06 9:47
leckey7-Jun-06 9:47 
GeneralRe: C#/SQL Question--New Problem Pin
Josh Smith7-Jun-06 9:51
Josh Smith7-Jun-06 9:51 
GeneralRe: C#/SQL Question--New Problem Pin
leckey7-Jun-06 9:58
leckey7-Jun-06 9:58 
GeneralRe: C#/SQL Question--New Problem Pin
Josh Smith7-Jun-06 10:12
Josh Smith7-Jun-06 10:12 
GeneralRe: C#/SQL Question--New Problem Pin
leckey7-Jun-06 10:20
leckey7-Jun-06 10:20 
GeneralRe: C#/SQL Question--New Problem Pin
Josh Smith7-Jun-06 10:38
Josh Smith7-Jun-06 10:38 
GeneralRe: C#/SQL Question--New Problem Pin
leckey7-Jun-06 10:44
leckey7-Jun-06 10:44 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.