asp.net 参数形式写sql

OracleConnection conn = c.GetConnection();
                OracleCommand cmd = new OracleCommand();
                cmd.Connection = conn;

cmd.CommandText = "update t_user set U_ACCOUNT=:U_ACCOUNT,U_NAME=:U_NAME,U_TYPE=:U_TYPE,U_COMPANY=:U_COMPANY where U_ID=:U_ID";
                    cmd.Parameters.Add(":U_ACCOUNT", OracleType.VarChar, 100).Value = account;
                    cmd.Parameters.Add(":U_NAME", OracleType.VarChar, 100).Value = username;
                    cmd.Parameters.Add(":U_TYPE", OracleType.VarChar, 100).Value = type;
                    cmd.Parameters.Add(":U_COMPANY", OracleType.VarChar, 100).Value = company;
                    cmd.Parameters.Add(":U_ID", OracleType.Number).Value = id;
conn.Open();
                cmd.ExecuteNonQuery();
                conn.Close();

原文地址:https://www.cnblogs.com/handsomer/p/3678242.html