using (SqlConnection connection =
new SqlConnection((@"Data Source=(local);Integrated Security=SSPI;"+"Initial Catalog=student"))
{
SqlDataAdapter adapter = new SqlDataAdapter();
adapter.SelectCommand = new SqlCommand("select * from 档案 where 学号='"+this.textBox1.Text+"' and 姓名='"+this.textBox2.Text+"'", connection);
DataTable dt=new DataTable();
da.Fill(dt);
this.dataGrid1.DataSource=dt;
this.dataGrid1.DataBind();
}
[/CODE]
[url=javascript:alert(1);] [div]fdgfdgfdg\" on\"[/div] [/url]