Hi guys,
I need to retrieve data from MS Access file (.mdb) using C# code.
I have to insert in the sql string, a value retrieved from a text box.
How do I prevent / avoid a
SQL Injection attack?
I thougth I can use the code below, but it's not working...
| // Create new SQLCommand. |
| System.Data.SqlClient.SqlCommand sqlCommand = new System.Data.SqlClient.SqlCommand(); |
| |
| // Set SQLCommand to Text type. |
| sqlCommand.CommandType = CommandType.Text; |
| |
| // Get the SQL String. |
| sqlCommand.CommandText = "SELECT * FROM Table1 WHERE Column1 = 'myUser'"; |
| // Insert the value from the text box into the string as parameterized value. |
| sqlCommand.Parameters.AddWithValue("myUser", myUser.Text); |
| |
Any help will be appreciated,
Aldo.