ms access - About SQL-injection in C# -
i visited link sql-injection. way use parameters is:
cmd.commandtext = "update [something_table] set = @something id = 1;"; var pparameter = new oledbparameter("@something", oledbtype.int); pparameter.value = something; cmd.parameters.add(pparameter);
but link says .parameters.addwithvalue
method simpler:
cmd.parameters.addwithvalue("@something", something);
what's main different between these? can choose addwithvalue
instead without consequences?
Comments
Post a Comment