paramter的添加
 public string GetUserIdByName(string UserName, string pwd)
    {
        string sql = @"select Namess from testlogin where UserName=@name and PWD=@PWD";
        MySqlConnection coon = new MySqlConnection(MySql);
        coon.Open();
        MySqlCommand cmd = new MySqlCommand(sql, coon);
        MySqlParameter sp;
        sp = new MySqlParameter("@name", UserName);
        cmd.Parameters.Add(sp);
        sp = new MySqlParameter("@PWD", pwd);
        cmd.Parameters.Add(sp);
        string result = cmd.ExecuteScalar().ToString();
        return result;
    }
                    
                
                
            
        
浙公网安备 33010602011771号