SqlCeCommand异常

时间:2012-10-22 14:03:58

标签: c# sql

我有这段代码:

SqlCeConnection connection = new SqlCeConnection(conString);
connection.Open();
connection.CreateCommand();
cmd.CommandText = "CREATE TABLE Settings (id int IDENTITY PRIMARY KEY, host nvarchar(50), port int, rk_host nvarchar(50), rk_port int, stationcode int, guesttypecode int)";
cmd.ExecuteNonQuery();
cmd = connection.CreateCommand();
cmd.CommandText = "INSERT INTO Settings ([host], [port], [rk_host], [rk_port], [stationcode], [guesttypecode]) VALUES ('" + Settings.host + "', '" + Settings.rk_host + "', '" + Settings.rk_port + "', '" + Settings.port + "', '" + Settings.stationcode + "', '" + Settings.guesttypecode + "')";
cmd.ExecuteNonQuery();
connection.Close();

在第二个ExecuteNonQuery上,我有一个例外:"Data conversion failed. [ OLE DB status value (if known) = 2 ]"

有人能帮助我吗?

2 个答案:

答案 0 :(得分:1)

在Int类型列上,您应该从查询中删除单引号

cmd.CommandText = "INSERT INTO Settings ([host], [port], [rk_host], [rk_port], [stationcode], [guesttypecode]) VALUES ('" + Settings.host + "', '" + Settings.rk_host + "', " + Settings.rk_port + ", '" + Settings.port + "', " + Settings.stationcode + ", " + Settings.guesttypecode + ")";

答案 1 :(得分:0)

第一个建议是永远不要写这样的查询,因为这会导致SQL Injection。其次,您正在从您的设置中读取并将其插入表中,而不考虑其类型。您需要输入转化(例如int.Parse(Settings.port)