Guest User

Untitled

a guest
Sep 20th, 2018
77
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.02 KB | None | 0 0
  1. var sql = "INSERT INTO myTable (myField1, myField2) " +
  2. "VALUES ('" + someVariable + "', '" + someTextBox.Text + "');";
  3.  
  4. var cmd = new SqlCommand(sql, myDbConnection);
  5. cmd.ExecuteNonQuery();
  6.  
  7. var sql = "INSERT INTO myTable (myField1, myField2) " +
  8. "VALUES (@someValue, @someOtherValue);";
  9.  
  10. using (var cmd = new SqlCommand(sql, myDbConnection))
  11. {
  12. cmd.Parameters.AddWithValue("@someValue", someVariable);
  13. cmd.Parameters.AddWithValue("@someOtherValue", someTextBox.Text);
  14. cmd.ExecuteNonQuery();
  15. }
  16.  
  17. var sql = "UPDATE myTable SET myField1 = @newValue WHERE myField2 = @someValue;";
  18.  
  19. // see above, same as INSERT
  20.  
  21. var sql = "SELECT myField1, myField2 FROM myTable WHERE myField3 = @someValue;";
  22.  
  23. using (var cmd = new SqlCommand(sql, myDbConnection))
  24. {
  25. cmd.Parameters.AddWithValue("@someValue", someVariable);
  26. using (var reader = cmd.ExecuteReader())
  27. {
  28. ...
  29. }
  30. // Alternatively: object result = cmd.ExecuteScalar();
  31. // if you are only interested in one value of one row.
  32. }
Add Comment
Please, Sign In to add comment