strSQL = "DELETE FROM member WHERE Email = '" + strUser + "' ";
objCmd = new MySqlCommand(strSQL, objConn);
objCmd.ExecuteNonQuery();
เป็น
Code (C#.NET)
strSQL = "DELETE FROM member WHERE Email = @email";
objCmd = new MySqlCommand(strSQL, objConn);
objCmd.Parameters.AddWithValue("email", strUser)
objCmd.ExecuteNonQuery();