The Error Producing Lines will be
total=float.Parse(dr[0].ToString());
float f=total+float.Parse(txcredit.Text);
And you are trying to convert what the user enters in the text box. What happens when the user does not type anything in the textbox.
Then you will get the exception .
And the front end make sure that user entered some valid values. It the user does not enter anything then try to pass a 0 as default value.
And don't contact values for query use the Parameter collection instead
And here is the example for the parameter collection
static void Main()
{
//
// The name we are trying to match.
//
string dogName = "Fido";
//
// Use preset string for connection and open it.
//
string connectionString = ConsoleApplication1.Properties.Settings.Default.ConnectionString;
using (SqlConnection connection = new SqlConnection(connectionString))
{
connection.Open();
//
// Description of SQL command:
// 1. It selects all cells from rows matching the name.
// 2. It uses LIKE operator because Name is a Text field.
// 3. @Name must be added as a new SqlParameter.
//
using (SqlCommand command = new SqlCommand("SELECT * FROM Tabble WHERE Name LIKE @Name", connection))
{
//
// Add new SqlParameter to the command.
//
command.Parameters.Add(new SqlParameter("Name", dogName));
//
// Read in the SELECT results.
//
SqlDataReader reader = command.ExecuteReader();
while (reader.Read())
{
int weight = reader.GetInt32(0);
string name = reader.GetString(1);
string breed = reader.GetString(2);
Console.WriteLine("ITem1 = {0}, Item2 = {1}, Item3 = {2}", weight, name, breed);
}
}
}
}
Parameter collection saves from SQL injection and data type conversion errors