User1741069310 posted
strsql = "update people set ";
strsql += "[Full Name]=@FullName, ";
strsql += "[Chinese Name]=@Chinese_Name, ";
strsql += "Department ='" + DDDepartment.SelectedItem.Text + "', ";
strsql += "Section ='" + DDSection.SelectedItem.Text + "', ";
strsql += "Position ='" + Position.Text + "', ";
strsql += "[Ext.]='" + Extension.Text + "', ";
strsql += "email = '" + Email.Text + "', ";
strsql += "Photo=@Photo2 ,";
strsql += "Company ='" + DDCompany.SelectedItem.Text + "', ";
strsql += "Loginname ='" + Email.Text.Substring(0, Email.Text.IndexOf("@")) + "', ";
strsql += "IsLeave='N' ";
strsql += "where [Staff ID]=" + StaffID.Text;
cmd = new System.Data.SqlClient.SqlCommand();
cmd.Connection = con;
cmd.CommandType = CommandType.Text;
cmd.CommandText = strsql;
cmd.Parameters.AddWithValue("@FullName", FullName.Text);
cmd.Parameters.AddWithValue("@Chinese_Name", Chinese_Name.Text);
cmd.Parameters.AddWithValue("@Photo2", imgByte);