protected void Search_Button_Click(object sender, EventArgs e) { Search_TextBox.Text = Search_TextBox.Text.ToUpper(); try { da = new SqlDataAdapter("SELECT SERIAL, FULLNAME FROM MEDINFO WHERE MNAME LIKE @MNAME + '%' ", con); da.SelectCommand.Parameters.Add(new SqlParameter("@MNAME", Search_TextBox.Text)); da.Fill(dt); Update_GridView.DataSource = dt; Update_GridView.DataBind(); } catch (Exception ee) { Response.Write("<script>alert('Medicine Does Not Exist')</script>"); } }
protected void Search_Button_Click(object sender, EventArgs e) { Search_TextBox.Text = Search_TextBox.Text.ToUpper(); try { //da = new SqlDataAdapter("SELECT SERIAL, FULLNAME FROM MEDINFO WHERE MNAME like '" + Search_TextBox.Text + "' '%' ", con); da = new SqlDataAdapter("SELECT SERIAL, FULLNAME FROM MEDINFO WHERE MNAME LIKE @MNAME + '%' ", con); da.SelectCommand.Parameters.Add(new SqlParameter("@MNAME", Search_TextBox.Text)); da.Fill(dt); Update_GridView.DataSource = dt; Update_GridView.DataBind(); } catch (Exception ee) { } }