
Untitled
By: a guest on
Jun 21st, 2012 | syntax:
None | size: 0.58 KB | hits: 10 | expires: Never
SQL Query and special chars
string Query1 =
"UPDATE message SET message = '" + mymessage + "' " +
"WHERE operationType = '" + value_operationType + "' " +
"AND languageType = '" + value_languageType + "';";
string htmlEncodedMessage = Server.HtmlEncode(mymessage);
string Query1 =
"UPDATE message SET message = '" + htmlEncodedMessage + "' " +
"WHERE operationType = '" + value_operationType + "' " +
"AND languageType = '" + value_languageType + "';";
<system.web>
...
<httpRuntime requestValidationMode="2.0" />
...
</system.web>