MySqlParameter usernameParameter = new MySqlParameter("?username", MySqlDbType.VarChar, 150); // You can use string patameterusernameParameter.Value = string (string)Session["username"];
cmd.Parameter.Add(usernameParameter);
MySqlParameter seekingParameter = new MySqlParameter("?seeking", MySqlDbType.Int32, 0); // You can use Integer Patameter
seekingParameter.Value = ddlseek.Text;
cmd.Parameter.Add(seekingParameter);
MySqlParameter agefromParameter = new MySqlParameter("?agefrom", MySqlDbType.Date, 0); // You can use date Patameter
agefromParameter.Value = ddlfrom.Text;
cmd.Parameter.Add(agefromParameter);
string SQL = " UPDATE tbl_users SET seeking = ?seeking, agefrom = ?agefrom Where username = ?username";MySqlCommand cmd = new MySqlCommand(SQL, conn);
conn.Open();
cmd.ExecuteNonQuery();
conn.Close();
Always use Paramters Coz is protected against SQL injection and easy to debug ;)