foreach (string str in TestWords)
{
//spam
SqlCommand cmd6 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='" + str + "' and files.spam=1 and folders.id<>" + FolIter + " and files.folderid<>" + FolIter + " and files.id='" + s[0].ToString + "'", cn);
int i6 = Convert.ToInt16(cmd6.ExecuteScalar());
double temp = Convert.ToDouble((i6 + 1)/(i7 + i8));
//non spam
**error**
SqlCommand cmd9 = new SqlCommand("select count from keys,files,folders where keys.fileid=files.id and keys.kname='"
+ str
+ "' and files.spam=0 and folders.id<>"
+ FolIter
+ " and files.folderid<>"
+ FolIter
+ " and files.id='"
+ s[0].ToString
+ "'", cn);
int i9 = Convert.ToInt16(cmd9.ExecuteScalar());
temp2 = Convert.ToDouble((i9 + 1)/(i7 + i8));
Sdoc = Convert.ToDouble(Sdoc * temp);
NsDoc = Convert.ToDouble(NsDoc * temp2);
}
错误IAM得到的是:操作“+”不能应用于类型“串”和“方法组”C#的SqlCommand错误
提供错误发生的行将是有益的,并且范围的其余部分。 – Kolky 2010-09-07 12:03:07
* FolIter *究竟是什么? – slugster 2010-09-07 12:04:55
两件事:1)什么是'FolIter'和2)(这一点很重要):做一些关于SQL注入的阅读(从这里开始,例如:http://msdn.microsoft.com/en-us/杂志/ cc163917.aspx)以及采取措施避免它。您的代码对于此类攻击广泛开放。 – 2010-09-07 12:06:17