防止注如入

  ChatCmd.Parameters.Add("@username", SqlDbType.Char).Value = UserNametxt;
            ChatCmd.CommandText = "select count(*) from " + Tabletxt + " where " + UserNameItem + "=@username";
            int AdminNameCount = Convert.ToInt16(ChatCmd.ExecuteScalar());
                if (AdminPassCount > 0)
                {

                    return "登录成功";

                }

你可能感兴趣的:(防止注如入)