Parameterized Command Example
Imports System Imports System.Data Imports System.Data.SqlClient Public Class MainClass Public Shared Sub ParameterizedCommandExample(ByVal con As SqlConnection, ByVal employeeID As Integer, ByVal title As String) Using com As SqlCommand = con.CreateCommand com.CommandType = CommandType.Text com.CommandText = "UPDATE HumanResources.Employee SET Title = @title WHERE EmployeeID = @id;" Dim p1 As SqlParameter = com.CreateParameter p1.ParameterName = "@title" p1.SqlDbType = SqlDbType.VarChar p1.Value = title com.Parameters.Add(p1) com.Parameters.Add("@id", SqlDbType.Int).Value = employeeID Dim result As Integer = com.ExecuteNonQuery Console.WriteLine(result) End Using End Sub Public Shared Sub Main() Using con As New SqlConnection con.ConnectionString = "Data Source=.\sqlexpress;Database=AdventureWorks;Integrated Security=SSPI;" con.Open() ParameterizedCommandExample(con, 16, "Production Technician") con.Close() End Using End Sub End Class