Parameterized query.
String query = "Select * from Member where username=?uname";
MySqlCommand cmd = new MySqlCommand(query, conn);
cmd.Parameters.Add("?uname",TextBox1.Text);
MySqlDataReader print = cmd.ExecuteReader();
bool read = print.Read();
string password = print.GetString(2);
__avd
Posting Genius (adatapost)
8,737 posts since Oct 2008
Reputation Points: 2,141
Solved Threads: 1,262
Skill Endorsements: 51