string.Format连接sql字符串

SqlConnection conn = new SqlConnection("server=.;integrated security=SSPI;;database=xiaobai");
         SqlCommand cmd;
        
private void btninsert_Click(object sender, EventArgs e)
         {
             conn.Open();
            
string _sql = "insert into login values('{0}','{1}','{2}')";

             _sql = string.Format(_sql, this.textBox1.Text.ToString().Trim(),this.textBox2.Text.ToString().Trim(),this.textBox3.Text.ToString().Trim());

             cmd
= new SqlCommand(_sql, conn);
             cmd.ExecuteNonQuery();
             conn.Close();
             MessageBox.Show(
"操作执行成功!");
         }

原文地址:https://www.cnblogs.com/zzxap/p/2175946.html