Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsWhite Papers
Discussion GroupsFirst AidDatabasesJavaBeansGUIJava 3DVirtual MachineCORBASecurityToolsGeneral
Java DirectoryOpen Source ProjectsSample Book ChaptersUser GroupsWeb Resources
Related Topics
Databases.NETMore Topics ...

Java Forum / Databases / February 2008

Tip: Looking for answers? Try searching our database.

how do i insert into databse?

Thread view: 
mak1084@gmail.com - 16 Feb 2008 14:14 GMT
i'm creating a an web application on attendance,  in which a user
after selecting the subject and month he gets all the student info
who
has taken that subject.

my problem is i'm able to get the multiple student with the text box
where a user can put up his monthly attendance. how do i insert the
info in database...at the same time after filling the info.

the snapshot of the code is here...
here I'm getting the roll no. along with the text box..

[code]
String str1 = "select roll_no from student where sem_id = (select
sem_id from subject where course_id ='bsc_it' and sub_id =
'"+getsub1+"')";

ResultSet rs  = stmt.executeQuery(str1);
                                                               %>
                                                       <table
align="center" width="" cellpadding="0" cellspacing="0"
border="1" cellspacing="1" cellpadding="1">

<tr>

<td><input type="text"  value="Total Lecture" readonly=""/></
td>

<td><input type="text" name="total_att" maxlength="2"></td>

</tr>

<tr>

<td><input type="text" value="Student roll no." readonly="" /
></td>


</tr>

<%                   while(rs.next())


{

%>


<%

stu_roll = rs.getString("roll_no");

%>

<tr bordercolor="#CC3366">

<td>

<%

out.println(stu_roll);

%>

</td>

<td>

<input type="text"  name="att" />

</td>

</tr>&nbsp;

                                                               <%
                                                                               }


con.close();
                                                                               }

catch(SQLException e)

{

out.println("Exception in SQL" + e);
                                                                               }
                                                               %>
[/code]
Robert Kochem - 16 Feb 2008 14:49 GMT
mak1084@gmail.com schrieb:

> [code]
> String str1 = "select roll_no from student where sem_id = (select
> sem_id from subject where course_id ='bsc_it' and sub_id =
> '"+getsub1+"')";

Please don't forget that creating SQL queries with user specified input
incorporates the possibility for an SQL injection attack. Therefore I
strongly recommend to change your code to use a PreparedStatement and set
the parameters via setInt() or SetString() - then your WebApp is secure
against such attacks.

http://java.sun.com/docs/books/tutorial/jdbc/basics/prepared.html

Robert


Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.