条件表达式中的数据类型不匹配


 myConnection.Open()
    rtb_Address.Clear()
    txt_Name.Clear()
    Dim str As String
    str = "SELECT * FROM table1 WHERE (cus_ID = '" & txt_ID.Text & "')"
    Dim cmd As OleDbCommand = New OleDbCommand(str, myConnection)
    dr = cmd.ExecuteReader()
    While dr.Read()
        rtb_Address.Text = dr("cus_Addr").ToString
        txt_Name.Text = dr("cus_Name").ToString
    End While
    myConnection.Close()

dr 中的错误 = cmd.ExecuteReader()

dr 被声明为 OleDbDataReader

cus_ID 可能是数值数据类型,但您尝试使用字符串进行查询:(cus_ID = 'thevalue')

只需删除封闭'(cus_ID = thevalue)

或者更好的是,使用参数化查询来防止 SQL 注入。

我会推荐以下内容:

 Using cmd As New OleDbCommand("SELECT * FROM table1 WHERE cus_ID = @ID", con)
    cmd.Parameters.AddWithValue("@ID", txt_ID.Text)
    dr = cmd.ExecuteReader()
    While dr.Read()
      rtb_Address.Text = dr("cus_Addr").ToString
      txt_Name.Text = dr("cus_Name").ToString
    End While
 End Using

相关内容

  • 没有找到相关文章

最新更新