//方法一:參數化查詢。缺點:增大資料庫的壓力 string ConnectionString="";//資料庫連接字串 string CustomerID = string.Empty; string CompanyName =string.Empty; string Address =string.Empty; using (SqlConnection cn = new SqlConnection(ConnectionString)) { cn.Open(); SqlCommand cmd = new SqlCommand("insert into Customers(CustomerID,CompanyName,Address) values(@CustomerID,@CompanyName,@Address)", cn); //cmd.Parameters.Add(new SqlParameter("@CustomerID", CustomerID)); 不會去與資料庫匹配 cmd.Parameters.Add("@CustomerID", SqlDbType.NChar, 5, CustomerID);//這種設定的資料類型,長度都必須與資料庫欄位一致 cmd.Parameters.Add("@CompanyName", SqlDbType.NVarChar, 40, CompanyName); cmd.Parameters.Add("@Address", SqlDbType.NVarChar, 60, Address); cmd.ExecuteNonQuery(); cn.Close(); }//方法二:過濾輸入的資訊,檢查是否存在危險字元。不必串連資料庫 /// <summary> /// 檢查輸入的資料 是否存在危險字元 /// </summary> /// <param name="sUser"></param> /// <param name="sPwd"></param> /// <returns>返回一個bool值</returns> public bool CheckData(string sUser, string sPwd) { if (sUser.IndexOf("'") != -1 || sPwd.IndexOf("%") != -1) { return false; } return true; }//方法三:使用預存程序(簡單代碼) string ConnectionString = "";//資料庫連接字串 string CustomerID = string.Empty; string CompanyName = string.Empty; string Address = string.Empty; using (SqlConnection cn = new SqlConnection(ConnectionString)) { cn.Open(); string Sql = "InsertUserProc";//預存程序名 SqlCommand cmd = new SqlCommand(Sql,cn); cmd.CommandType = CommandType.StoredProcedure; cmd.ExecuteNonQuery(); cn.Close(); }