protected void btnSearch_Click(object sender, EventArgs e) { String cmd = "SELECT [CustomerID], [CompanyName], [ContactName] FROM [Customers] WHERE CompanyName ='" + txtCompanyName.Text + "'"; SqlDataSource1.SelectCommand = cmd; GridView1.Visible = true; }
SELECT [CustomerID], [CompanyName], [ContactName] FROM [Customers] WHERE CompanyName ='Oracle' UNION SELECT CustomerID, ShipName, ShipAddress FROM ORDERS--'

| 第1页: 什么是SQL注入 | 第2页: SQL注入攻击剖析 |
| 第3页: 典型的SQL安全防护 | 第4页: LINQ概述 |
| 第5页: 通过LINQ使数据访问更安全 |