1、传参时有可能出现SQL语句注入
StringBuffer sb = new StringBuffer();
if(StringUtils.isNotBlank(areaCode))
{
sb.append("and t.area_code = ‘").append(areaCode).append("‘ ");
}
SQLQuery query = getSession().createSQLQuery(sb.toString());
StringBuffer sb = new StringBuffer();
if(StringUtils.isNotBlank(areaCode))
{
sb.append("and t.area_code = :areaCode ");
}
SQLQuery query = getSession().createSQLQuery(sb.toString());
if(StringUtils.isNotBlank(areaCode))
{
query.setParameter("areaCode",areaCode);
}原文:http://blog.csdn.net/you23hai45/article/details/19131235