Conn.Open()
Dim strSel As String = "select vcEvent from diary where vcEvent like '%" & txtValue.Text & "%'"
Dim Cmd As New SqlCommand(strSel, Conn)
Dim Dreader As SqlDataReader = Cmd.ExecuteReader
Dim strSel As String = "select vcEvent from diary where vcEvent like '%" & txtValue.Text & "%'"
Dim Cmd As New SqlCommand(strSel, Conn)
Dim Dreader As SqlDataReader = Cmd.ExecuteReader
http://chs.gotdotnet.com/quickstart/aspplus/doc/webdataaccess.aspx#param
当然,如果要避免用户输入单引号而引起问题,可以这样做:
Dim strSel As String = "select vcEvent from diary where vcEvent like '%" & Replace(txtValue.Text,"'","''") & "%'"