我想這EXCUTE SQL查詢SQL子查詢語法asp.net
Dim str As String = "UPDATE table1 SET " & _
"number = '" & strc & "'," & _
"code = '" & "123" & "'," & _
"line= '" & dd1.text & "'," & _
"sellr = '" & txtrun.text & "'," & _
"endu= '" & txtex1.value+txtex2.value & "'" & _
"WHERE number IN (select table1.number" & _
"FROM table1 INNER JOIN table2 ON table1.number = table2.number" & _
"WHERE ((table1.username)='" & session("username") & "' AND (table1.pass)='" & session("pass") & "' AND (table2.sellnum)='" & session("sellnum") & "'));"
存在查詢表達式語法錯誤,這是德我第一次使用嵌套子查詢
所有領域越來越字符串的值
所以,如果有人能告訴我什麼是寫這個查詢正確的方法我會
您的代碼可以廣泛應用於[SQL注入](http://en.wikipedia.org/wiki/SQL_injection)。您應該使用參數化查詢。 – Oded
同意Oded ...創建一個存儲過程,它接受這些參數並進行更新。 –