how to get sting value in query | Sololearn: Learn to code for FREE!
New course! Every coder should learn Generative AI!
Try a free lesson
0

how to get sting value in query

System.out.print("Enter MName= "); mname=br.readLine(); su ="UPDATE contact SET mname= "+ mname +" WHERE id="+cid; System.out.println(su); n=s.executeUpdate(su);

1st Jun 2023, 5:47 PM
Sahil Kshirsagar
Sahil Kshirsagar - avatar
2 Answers
+ 4
You should never use string concatenation to write SQL. This is how you can fall victim to code injection attacks. You should use PreparedStatement instead, as suggested in the stackoverflow article linked by Sakshi. https://www.baeldung.com/java-statement-preparedstatement
1st Jun 2023, 8:26 PM
Tibor Santa
Tibor Santa - avatar