防注入查询

SqlParameter[] sps = new SqlParameter[]
            {
                new SqlParameter("@name", "%" + name + "%")
            };

原文地址:https://www.cnblogs.com/daixingqing/p/2768420.html