I have a query like this:
SELECT * FROM Table1 WHERE Column1 = {0} AND Column2 = {1}
And I want to execute that statement and send a list of parameters that contains values which should replace {0} and {1}. A list of objects with 2 elements.
I have only found solution with named parameters by now, but I dont want named parameters, I want to do it in the way specified above...
parameterized query? It's really bad approach and opens your app for SQL injection attack.string.Formatdoes not prevent SQL Injection attacks. Consider to using parameterized statements instead.