string
sql =
"update Table1 set name = 'Pudding' where ID = '1'"
;
//未采用SqlParameter
SqlConnection conn =
new
SqlConnection();
conn.ConnectionString =
"Data Source=.\\SQLExpress;Integrated Security=true;AttachDbFilename=|DataDirectory|\\Database.mdf;User Instance=true"
;
//连接字符串与数据库有关
SqlCommand cmd =
new
SqlCommand(sql, conn);
try
{
conn.Open();
return
(cmd.ExecuteNonQuery());
}
catch
(Exception)
{
return
-1;
throw
;
}
finally
{
conn.Close();
}
1.ADD方法
SqlParameter sp =
new
SqlParameter(
"@name"
,
"Pudding"
);
cmd.Parameters.Add(sp);
sp =
new
SqlParameter(
"@ID"
,
"1"
);
cmd.Parameters.Add(sp);
2.ADDRANGE方法
SqlParameter[] paras =
new
SqlParameter[] {
new
SqlParameter(
"@name"
,
"Pudding"
),
new
SqlParameter(
"@ID"
,
"1"
) };
cmd.Parameters.AddRange(paras);