sql server 存储过程中拼接sql,转义单引号

DECLARE @col VARCHAR(9) ,

DECLARE @val VARCHAR(100)

SET @col = 'firstname'

EXEC('SELECT * FROM table WHERE firstname like ''%' +@val+'%'' ORDER BY '+@col)

GO
原文地址:https://www.cnblogs.com/booth/p/2244364.html