1. escape_string MySQLdb.escape_string() 2. excute参数化传递 excute(sql, (str1,str2)) 代码 12345678910 import MySQLdbconn = MySQLdb.connect(host='localhost', user='root', passwd='', db='test')param = 'aaa'escape_param = MySQLdb.escape_string(param)cur = conn.cursor()cur.execute("select * form table where col="+escape_param+"")cur.commit()cur.close() 赞微海报分享
近期评论