ms access - About SQL-injection in C# -


i visited link sql-injection. way use parameters is:

 cmd.commandtext = "update [something_table] set = @something id = 1;";   var pparameter = new oledbparameter("@something", oledbtype.int);                         pparameter.value = something;                         cmd.parameters.add(pparameter);   

but link says .parameters.addwithvalue method simpler:

cmd.parameters.addwithvalue("@something", something); 

what's main different between these? can choose addwithvalue instead without consequences?


Comments

Popular posts from this blog

sql - invalid in the select list because it is not contained in either an aggregate function -

Angularjs unit testing - ng-disabled not working when adding text to textarea -

How to start daemon on android by adb -