Variable column names using prepared statements

后端 未结 7 744

I was wondering if there was anyway to specify returned column names using prepared statements.

I am using MySQL and Java.

When I try it:

St         


        
7条回答
  •  误落风尘
    2020-11-22 08:54

    Use sql injection disadvantage of Statement Interface as advantage. Ex:

    st=conn.createStatement();
    String columnName="name";
    rs=st.executeQuery("select "+ columnName+" from ad_org ");
    

提交回复
热议问题