vb.net escape reserved keywords in sql statement

后端 未结 2 1422
猫巷女王i
猫巷女王i 2020-12-22 08:12

I\'m trying to execute an sql statement in vb.net to an Access database, I am escaping the reserverd word using square brackets []. This has worked in all my SELECT

2条回答
  •  被撕碎了的回忆
    2020-12-22 08:27

    Always use parameters. What you're doing is very dangerous and leaves the door open to SQL injection.

    Then you won't have to worry about escaping the values you're inserting into the database.

提交回复
热议问题