public void create() { string sql = "INSERT INTO Users(email, password, firstName, lastName, address, city, state, zipcode) VALUES('" + email + "', '" + CreateMD5Hash(password) + "', '" + firstName + "', '" + lastName + "', '" + address + "', '" + city + "', '" + state + "', '" + zipcode + "')"; SQLfunctions sf = new SQLfunctions(); sf.executeSQL(sql); }
public void addLoan() { UserInfo user = (UserInfo)HttpContext.Current.Session["pl_user"]; string sql = "INSERT INTO Loan(userID, b_email, b_firstName, b_lastName, loanDate, amount, rate, term, loanNumber) VALUES(" + user.userID + ", '" + b_Email + "', '" + b_firstName + "', '" + b_lastName + "', '" + loanDate + "', " + amount + ", " + rate + ", " + term + ", '" + loanNumber + "')"; SQLfunctions sf = new SQLfunctions(); sf.executeSQL(sql); }