troubleshooting Question

how to insert char into string in C#

Avatar of dipster307
dipster307 asked on
ASP.NET
4 Comments2 Solutions1660 ViewsLast Modified:
The problem I am having in execute sql statements when special characters are entered into the text box.

The method I am trying is to check the string in the textbox. And insert the escape character just before the special character so the sql statement will execute without error.
My code is below:

       
String stgName = txtUsername.Text;
        String stgNewName = txtUsername.Text + txtUsername.Text;
        for (int i = 0; i < stgName.Length; i++)
        {
            if (stgName[i] == '\'')
            {
                stgNewName.Insert(i,"\\");
                stgNewName.Insert(i + 1, stgName[i].ToString());
                
            }
            else
            {
                stgNewName.Insert(i, stgName[i].ToString());
            }
        }


            SqlCommand comm = new SqlCommand("SELECT * FROM LoginTable WHERE userName='" + txtUsername.Text + "' AND userPass='" + txtPassword.Text + "'", conn);
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 2 Answers and 4 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 4 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros