<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META content="text/html; charset=windows-1257" http-equiv=Content-Type> <META name=GENERATOR content="MSHTML 8.00.6001.18904"> <STYLE></STYLE> </HEAD> <BODY> <DIV><FONT size=2 face=Arial>SqlCommand cmd = new SqlCommand(<FONT color=#ff0000>string.Format(</FONT>"DELETE FROM Detail WHERE MasterUUID = @MasterUUID"); </FONT></DIV> <DIV><FONT size=2 face=Arial>cmd.Parameters.Add("@MasterUUID",masterUUIDParameter);</FONT></DIV> <DIV> <DIV><FONT size=2 face=Arial><STRONG>cmd.Prepare(); </STRONG></FONT></DIV> <DIV><FONT size=2 face=Arial>cmd.ExecuteNonQuery();</FONT></DIV> <DIV><FONT size=2 face=Arial>cmd.Parameters[0].Value = masterUUIDParameter2;</FONT></DIV> <DIV><FONT size=2 face=Arial> <DIV><FONT size=2 face=Arial>cmd.ExecuteNonQuery();</FONT></DIV></FONT></DIV></DIV> <DIV><FONT size=2 face=Arial></FONT> </DIV> <DIV><FONT size=2 face=Arial><A href="http://msdn.microsoft.com/en-us/library/system.data.sqlclient.sqlcommand.prepare%28VS.71%29.aspx">http://msdn.microsoft.com/en-us/library/system.data.sqlclient.sqlcommand.prepare%28VS.71%29.aspx</A></DIV></FONT> <DIV><FONT size=2 face=Arial></FONT> </DIV> <DIV><FONT size=2 face=Arial></FONT> </DIV> <DIV><FONT size=2 face=Arial>O iaip pirmas bdas atviras SQL injection'ams :)</FONT></DIV> <DIV><FONT size=2 face=Arial>SqlCommand cmd = new SqlCommand(string.Format("DELETE FROM Detail WHERE MasterUUID = '{0}'", masterUUID)); <BR><BR></FONT></DIV> <DIV><FONT size=2 face=Arial>"Meff" <</FONT><A href="mailto:noemail@japan.cc"><FONT size=2 face=Arial>noemail@japan.cc</FONT></A><FONT size=2 face=Arial>> wrote in message </FONT><A href="news:hs9agt$qek$1@trimpas.omnitel.net"><FONT size=2 face=Arial>news:hs9agt$qek$1@trimpas.omnitel.net</FONT></A><FONT size=2 face=Arial>...</FONT></DIV><FONT size=2 face=Arial>> Sveiki. domumo dlei ....<BR></FONT></BODY></HTML>