Always use parameterized queries.
Sample:
Dim cn As New MySqlConnection("Server=localhost;Database=testdb;Uid=root;Pwd=;")
Dim cmd As New MySqlCommand
cmd.CommandText = "update testTable set col1=?p1, col2=?p2 where col3=?p3"
cmd.Connection = cn
cmd.Parameters.AddWithValue("?p1", value1)
cmd.Parameters.AddWithValue("?p2", value2)
cmd.Parameters.AddWithValue("?p3", value3)
cn.Open()
cmd.ExecuteNonQuery()
cn.Close()
__avd
Posting Genius (adatapost)
8,648 posts since Oct 2008
Reputation Points: 2,136
Solved Threads: 1,241
What I am suggesting that you have to rewrite code using Parameter. If you're stuck post what you have.
__avd
Posting Genius (adatapost)
8,648 posts since Oct 2008
Reputation Points: 2,136
Solved Threads: 1,241