c# 4.0 - How to insert data in mysql database using C# -


string query2 = "insert library_database.status_of_issue values('"; query2 = query2 +textbox2.text + "','"; query2 = query2 + textbox1.text + "', curdate(),adddate(curdate(), interval 14 day)"; cmd = new mysqlcommand(query2, con); mysqldatareader d1 = cmd.executereader(); messagebox.show("issed..."); d1.close(); 

missing closing parenthesys values clause, query should rewritten avoid sql injection , insert query executed executenonquery

string query2 = @"insert library_database.status_of_issue values(@p1, @p2,                   curdate(),adddate(curdate(), interval 14 day))"; cmd = new mysqlcommand(query2, con); cmd.parameters.addwithvalue("@p1", textbox2.text); cmd.parameters.addwithvalue("@p2", textbox1.text); int rows = cmd.executenonquery(); if(rows > 0)      messagebox.show("insert ok..."); 

Comments

Popular posts from this blog

javascript - how to protect a flash video from refresh? -

android - Associate same looper with different threads -

visual studio 2010 - Connect to informix database windows form application -