using (SqlConnection conn = new SqlConnection("Data Source=.;Initial Catalog=OCTOP;User ID=sa;Password=1"))
            {
                conn.Open();
                using (SqlCommand cmd = conn.CreateCommand())
                {
                    //SQL语句参数化,但是表名、字段名、select、where 等关键字不能参数化
                    cmd.CommandText = "select * from bdBMDA where pk_corp=@pkCorp";
                    cmd.Parameters.Add(new SqlParameter("@pkCorp","9001"));

                    //SqlDataAdapter用于将执行结果填充至DataSet中。
                    SqlDataAdapter adapter = new SqlDataAdapter(cmd);
                    DataSet dataset = new DataSet();
                    adapter.Fill(dataset);

                    //
                    DataTable table = dataset.Tables[0];
                    DataRowCollection rows = table.Rows;
                    for (int i = 0; i < rows.Count; i++)
                    {
                        DataRow row = rows[i];
                        string deptname = (string)row[2];
                        MessageBox.Show(deptname);
                    }

                }
            }

posted on 2014-03-04 22:40  恩恩爸爸  阅读(88)  评论(0)    收藏  举报