April 4, 2011 23:20 by fengelz

using System.Data;
using System.Data.SqlClient;
using System.Configuration;
var connectionStr = ConfigurationManager.ConnectionStrings["myconnection"].ConnectionString;
SqlCommand cmd = new SqlCommand();
cmd.Connection = new SqlConnection(CONNECTIONSTR);
cmd.Parameters.Add(new SqlParameter("@name", name));
cmd.Parameters.Add(new SqlParameter("@lastName", lastName));
cmd.Parameters.Add(new SqlParameter("@date",DateTime.Now));
cmd.CommandText =
            "INSERT INTO myTable (email, bannerType, score, name, lastName, date) " +
            "VALUES (@email, @bannerType, @score, @name, @lastName, @date)";

var rowsAffected = cmd.ExecuteNonQuery();
return rowsAffected;

Not that theres anything new to this. In fact its very old fashioned, but If you like me forget how its done; snip it.

Inserting Data With C# and parameterized values

sql, c#

