日期:2014-05-18 浏览次数:20707 次
import java.sql.Statement;
import java.sql.ResultSet;
import javax.servlet.http.HttpServletRequest;
public class myInjection {
Statement statement=new Statement();//这边为什么报错
public void testMethod(HttpServletRequest request){
StringBuffer sqlStatement=
new StringBuffer(
"select * from employee where userid=");
String id=request.getParameter("userid");
if(id!=null)
sqlStatement.append(id);
else
sqlStatement.append("");
ResultSet results=statement.executeQuery(sqlStatement.toString());
}
}
Connection cc=DriverManager.getConnection("", "", "");
Statement st=cc.createStatement();