===>
strMysql="select * from USER_INFO where USERNAME = ?";
oraCmd.CommandText=strMysql;
oraCmd.Parameters.Add("@username",txt_UserName.Text);
oraReader=oraCmd.ExecuteReader();