今天犯了个大错

    public static void ChangeGoodsCounts(int GoodsID, int changCounts)
{ int lastCount;
using (SqlConnection conn = new SqlConnection(connStr))
{
conn.Open();
using (SqlCommand cmd = conn.CreateCommand())
{
cmd.CommandText = "select GoodsCounts from GoodsInf where GoodsID=" + GoodsID;
int counts=Convert.ToInt32(cmd.ExecuteScalar());
lastCount = counts + changCounts; cmd.CommandText = "update GoodsInf set GoodsCounts='"+lastCount+"' where GoodsID=" + GoodsID;
cmd.ExecuteNonQuery(); } }
}

http://www.tup.tsinghua.edu.cn/Resource/tsyz/030095-01.txt

05-08 14:53