15-6-2008 7:52:23
Public Const INSERT_VIDEOS As String = "INSERT INTO [Videos] (Tieu_de, Video) " _
+ " VALUES (@Tieu_de, @Video)"
Public Function Insert(ByVal myVideos As cVideos_Info) As Integer
Dim result As Integer = 0
Try
Dim Param(1) As SqlParameter
Param(0) = New SqlParameter("@Tieu_de", myVideos.Tieu_de)
Param(1) = New SqlParameter("@Video", myVideos.Video)
result = UDB.Execute(INSERT_VIDEOS, Param)
Catch ex As Exception
Throw ex
End Try
Return result
End Function
đây là 1 đoạn code vấn đề là tại sao nên dùng SqlParameter?