Select Parameterized SQL Command...


 private void Button1_Click(System.Object sender, System.EventArgs e)
{
	SqlConnection con = new SqlConnection("Data Source=.\\SQLEXPRESS;AttachDbFilename=|DataDirectory|\\Database1.mdf;Integrated Security=True;User Instance=True");
	SqlCommand cmd = new SqlCommand();
	cmd.CommandType = CommandType.Text;
	cmd.CommandText = "SELECT StudentIdID, StudentName FROM Students WHERE StudentName LIKE @studName";
	cmd.Connection = con;
	SqlParameter StudentNameParameter = new SqlParameter("@studName", "g%");
	cmd.Parameters.Add(StudentNameParameter);
}