Get Help:Ask a Question in our Forums|Report a Bug|More Help Resources
Last post Aug 04, 2010 04:35 PM by mohitdixit
Apr 23, 2009 10:53 AM|LINK
Thanks for the links.I have added sql helper dll in my website but i didnt get sqlhelper.cs in app_code.how to get into app_code folder.
If you have Assembly then what is need of .cs file,
Is that true that sql helper class cauese sql injections.
Yes, there is lot of chance if you use CommandText as Text,
i.e, you are using inline sql. U must use SQL Store Procedure.
For Example you write command Text as
Column1='"+TextBox1.Text "' and Column2='"+TextBox2.Text "'
If I Enter in TextBox1.Text = ' OR 1=1 --
then simply always true because 1=1 and -- comment after remaining code
Aug 04, 2010 04:35 PM|LINK
Here is the link i give to you where you can download the sqlhelper file......
Happy Coding Bro ......