jdbc防止sql注入-PreparedStatement
时间:2021-07-01 10:21:17
帮助过:14人阅读
ResultSet rs = null;
PreparedStatement stat = null;
Connection conn = null;
List list = new ArrayList();
try {
conn = createConnection();
String sql = "select name,password from manager where name=? and password=? ";
stat = conn.prepareStatement(sql);
stat.setString(1, name);
stat.setString(2, password);
rs = stat.executeQuery();
while (rs.next()) {
System.out.println(rs.getString(1));
String []user = new String[2];
user[0] = rs.getString(1);
user[1] = rs.getString(2);
list.add(user);
}
} catch (Exception e) {
e.printStackTrace();
} finally {
closeAll(rs, stat, conn);
}
return list;
}
版权声明:本文为博主http://www.zuiniusn.com原创文章,未经博主允许不得转载。
jdbc防止sql注入-PreparedStatement
标签:sql注入