SqlConnection conn = new SqlConnection(connStr); string sql= "update [userInfo] set xc02= @xc02,passWord = @password, ask = @ask WHERE userName= @username"; SqlCommand cmd = new SqlCommand(sql,conn) sqlParameter[] sqlParas = new sqlPararmeter[]{ new SqlParameter("@xc02",string xc02), new SqlParameter("@password",string password), new SqlParameter("@username",string username) } foreach(SqlParameter sp in sqlParas) { cmd.Parameters.add(sp); } conn.open(); cmd.ExecuteNonQuery();