Don't like ads? PRO users don't see any ads ;-)
Guest

Untitled

By: a guest on Jun 21st, 2012  |  syntax: None  |  size: 0.58 KB  |  hits: 10  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. SQL Query and special chars
  2. string Query1 =
  3.     "UPDATE message SET message = '" + mymessage + "' " +
  4.     "WHERE  operationType = '" + value_operationType + "' " +
  5.     "AND    languageType = '" + value_languageType + "';";
  6.        
  7. string htmlEncodedMessage = Server.HtmlEncode(mymessage);
  8.  
  9. string Query1 =
  10.     "UPDATE message SET message = '" + htmlEncodedMessage + "' " +
  11.     "WHERE  operationType = '" + value_operationType + "' " +
  12.     "AND    languageType = '" + value_languageType + "';";
  13.        
  14. <system.web>
  15.    ...  
  16.    <httpRuntime requestValidationMode="2.0" />
  17.    ...
  18. </system.web>