security - Single quote character in query string causes SQL injection -


i wondering if adding single quote mark embedded query string parameter in hard coded sql query cause sql injection error? can see after @docnum parameter using both percent , single quote characters. somewhere in code causing error. if use single percent character % instead of both % , single quote character %' unlike in stringbuilder appended line below stop error occurring?

sb.append("and docnumtcn  thumbsdown @docnum%' " );  

if i'm correct here, suspect you're trying document number can like another. perhaps you're trying achieve this:

sb.append("and docnumtcn '%' + @docnum + '%' ") 

the confusing part thumbsdown field you've got in there.


Comments

Popular posts from this blog

python - No exponential form of the z-axis in matplotlib-3D-plots -

php - Best Light server (Linux + Web server + Database) for Raspberry Pi -

c# - "Newtonsoft.Json.JsonSerializationException unable to find constructor to use for types" error when deserializing class -