1、SQL语句带参数的
(1)、

public static int Updata(string sql)

{

SqlConnection conn = new SqlConnection(connString);

SqlCommand cmd = new SqlCommand(sql, conn);

try

{

conn.Open();

return cmd.ExecuteNonQuery();

}

catch (Exception ex)

{
throw ex;
        }
        finally
        {
            conn.Close();
        }
      }

  (2)
      public static int Updata(string sql,,SqlParameter[] param)
    {
        SqlConnection conn = new SqlConnection(connString);
        SqlCommand cmd = new SqlCommand(sql, conn);
        try
        {
            conn.Open();
            cmd.Parameters.AddRange(param)
            return cmd.ExecuteNonQuery();
        }
        catch (Exception ex)
        {

            throw ex;
        }
        finally
        {
            conn.Close();
        }
      }
    3:SQL语言
      string sql=“Select LoginId,LoginPWD from Admin Where LoginId=@LoginId and LoginPWD=@LogindPWD”;
      SqlParameter[] parameter= new SqlParameter[]
      {
          new SqlParameter("@LoginId",objAdmin.LoginId),
           new SqlParameter("@LoginPWD",objAdmin.LoginPWD),
      }