C# SQL防注入

string sql = "select * from student where id like" +"@key";
Sqlconnection con = new Sqlconnetion();
Sqlcommand com =new Sqlcommand();
SqlParameter prmid = new SqlParameter();
prmid.ParameterName = "@key";
prmid.Value=key;
com.Parameters.Add(prmid);
原文地址:https://www.cnblogs.com/shuize/p/7483833.html