473,508 Members | 2,091 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

SQL query in vb.net

Here's what I've got:
*****************************
Dim postalcode As String
postalcode = txtpostalcode.Text
Dim title As String
title = ddltitle.SelectedItem.Text
Dim sqlStr As String = "SELECT DISTINCT Last_Name FROM " & PubName & "
WHERE PostalCode=" & postalcode And " Title=" & title ORDER BY
Last_Name"

***********************
Last_Name, PostalCode and Title are columns in my table.
My table is referenced as PubName from a drop dow list.
I just want to know were the error is in this sqlStr since it always
gives me an error in that line. I'm pretty sure it has to do with the
symbols (& " = ). I just can't seem to get it right.
Any clues ??
Thanks
JMT

Jul 23 '05 #1
2 1353
Hi

WHERE PostalCode=" & postalcode And " Title=" & title ORDER BY
Last_Name"

should be:

WHERE PostalCode=" & postalcode & " And Title = " & title & " ORDER BY
Last_Name"

You may want to enquote postalcode and title
WHERE PostalCode = '" & postalcode & "' And Title = '" & title & "' ORDER BY
Last_Name"

John

"vbnetrookie" <bi****@hotmail.com> wrote in message
news:11**********************@g44g2000cwa.googlegr oups.com...
Here's what I've got:
*****************************
Dim postalcode As String
postalcode = txtpostalcode.Text
Dim title As String
title = ddltitle.SelectedItem.Text
Dim sqlStr As String = "SELECT DISTINCT Last_Name FROM " & PubName & "
WHERE PostalCode=" & postalcode And " Title=" & title ORDER BY
Last_Name"

***********************
Last_Name, PostalCode and Title are columns in my table.
My table is referenced as PubName from a drop dow list.
I just want to know were the error is in this sqlStr since it always
gives me an error in that line. I'm pretty sure it has to do with the
symbols (& " = ). I just can't seem to get it right.
Any clues ??
Thanks
JMT

Jul 23 '05 #2
vbnetrookie (bi****@hotmail.com) writes:
Here's what I've got:
*****************************
Dim postalcode As String
postalcode = txtpostalcode.Text
Dim title As String
title = ddltitle.SelectedItem.Text
Dim sqlStr As String = "SELECT DISTINCT Last_Name FROM " & PubName & "
WHERE PostalCode=" & postalcode And " Title=" & title ORDER BY
Last_Name"

***********************
Last_Name, PostalCode and Title are columns in my table.
My table is referenced as PubName from a drop dow list.
I just want to know were the error is in this sqlStr since it always
gives me an error in that line. I'm pretty sure it has to do with the
symbols (& " = ). I just can't seem to get it right.


Don't build complete SQL strings like this. Use the parameter object
to supply your parameters:

Dim sqlStr As String = "SELECT DISTINCT Last_Name FROM " & PubName & "
WHERE PostalCode= @postalcode And Title = @title ORDER BY LastName

Then use .AddParameter to defined @postalcode and @title. What you
are trying to do above, is open for a security problem known as SQL
injection.

Also, I don't know why PubBane is a variable - dynamic selection of
table names usually indicates poor database design.

--
Erland Sommarskog, SQL Server MVP, es****@sommarskog.se

Books Online for SQL Server SP3 at
http://www.microsoft.com/sql/techinf...2000/books.asp
Jul 23 '05 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
3413
by: jaysonsch | last post by:
Hello! I am having some problems with a database query that I am trying to do. I am trying to develop a way to search a database for an entry and then edit the existing values. Upon submit, the...
29
2477
by: shank | last post by:
1) I'm getting this error: Syntax error (missing operator) in query expression on the below statement. Can I get some advice. 2) I searched ASPFAQ and came up blank. Where can find the "rules"...
9
3109
by: netpurpose | last post by:
I need to extract data from this table to find the lowest prices of each product as of today. The product will be listed/grouped by the name only, discarding the product code - I use...
3
5372
by: Harvey | last post by:
Hi, I try to write an asp query form that lets client search any text-string and display all pages in my web server that contain the text. I have IIS 6.0 on a server 2003. The MSDN site says...
4
2133
by: Diamondback | last post by:
I have two tables, WIDGETS and VERSIONS. The WIDGETS table has descriptive information about the widgets while the VERSIONS table contains IDs relating to different iterations of those widgets...
14
3853
by: Dave Thomas | last post by:
If I have a table set up like this: Name | VARCHAR Email | VARCHAR Age | TINYINT | NULL (Default: NULL) And I want the user to enter his or her name, email, and age - but AGE is optional. ...
0
3484
by: starace | last post by:
I have designed a form that has 5 different list boxes where the selections within each are used as criteria in building a dynamic query. Some boxes are set for multiple selections but these list...
6
4815
by: jjturon | last post by:
Can anyone help me?? I am trying to pass a Select Query variable to a table using Dlookup and return the value to same select query but to another field. Ex. SalesManID ...
4
3113
by: Stan | last post by:
I am using MS Office Access 2003 (11.5614). My basic question is can I run a query of a query datasheet. I want to use more that one criteria and can not get that query to work. I thought I...
6
4373
by: jsacrey | last post by:
Hey everybody, got a secnario for ya that I need a bit of help with. Access 97 using linked tables from an SQL Server 2000 machine. I've created a simple query using two tables joined by one...
0
7124
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
0
7326
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
7385
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
1
7046
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
7498
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
1
5053
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...
0
4707
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and...
0
3195
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The...
0
1558
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated ...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.