public void InsertSponsorRecord(USTTI.Base.Sponsor sponsor) { string sql = "INSERT INTO sponsors VALUES(" + sponsor.SponsorID + ",'" + sponsor.SponsorName + "','" + sponsor.SponsorAbbr + "','" + sponsor.Contact + "','" + sponsor.Address + "','','" + sponsor.City + "','" + sponsor.State + "','" + sponsor.Phone1 + "','" + sponsor.Phone2 + "','" + sponsor.Fax + "','" + sponsor.Email + "','" + sponsor.Comment + "')"; ExecuteNonQuery(sql); }
public void UpdateSponsorRecord(USTTI.Base.Sponsor sponsor) { string sql = "UPDATE sponsors SET sponsname='" + sponsor.SponsorName + "',sponsabbr='" + sponsor.SponsorAbbr + "',contact='" + sponsor.Contact + "',address1='" + sponsor.Address + "',address2='',city='" + sponsor.City + "',state='" + sponsor.State + "',phone1='" + sponsor.Phone1 + "',phone2='" + sponsor.Phone2 + "',fax='" + sponsor.Fax + "',email='" + sponsor.Email + "',comments='" + sponsor.Comment + "' WHERE sponsid=" + sponsor.SponsorID; ExecuteNonQuery(sql); }