62,254
社区成员
发帖
与我相关
我的任务
分享
using System;
using System.Collections;
using System.Text;
using System.Data;
using Microsoft.ApplicationBlocks.Data;
using System.Data.SqlClient;
namespace ClothingCode
{
/// <summary>
/// 管理员后台对网站广告的添加和删除
/// </summary>
public class AD
{
/// <summary>
/// 添加广告
/// </summary>
/// <param name="c_AD">广告实体</param>
public void InsertAD(ClothingCode.ADEntity c_AD)
{
string sqlString = "insert into [C_AD](ADTitle,ADContent,ADType,ADPhoto,ADUrl)" +
"values(N'" + c_AD.ADTitle + "',N'" + c_AD.ADContent + "'," + c_AD.ADType + ",N'" + c_AD.ADPhoto + "',N'" + c_AD.ADUrl + "')";
object obj = SqlHelper.ExecuteNonQuery(ClothingCode.ClothingSystem.ConnString, CommandType.Text, sqlString);
}
/// <summary>
/// 删除广告
/// </summary>
/// <param name="c_AD">广告实体</param>
public void DeleteADAdmin(ClothingCode.ADEntity c_AD)
{
string sqlString = "delete from C_AD where ADID=" + c_AD.ADID + "";
SqlHelper.ExecuteNonQuery(ClothingCode.ClothingSystem.ConnString, CommandType.Text, sqlString);
}
}
}
public static string FilterVal(string Val)
{
if (string.IsNullOrEmpty(Val))
return "";
string value = Val;
//防SQL注入
value = value.Replace("'", "");
value = value.Replace("--", "");
value = value.Replace(";", ";");
//过滤JS和HTML
value = value.Replace("&", "&");
value = value.Replace("<", "<");
value = value.Replace(">", ">");
value = value.Replace("\"", """);
value = value.Replace("'", "'");
return value;
}