Hi Team,
After veracode scanning(static and dynamic),i got SQL injection flaw for perticular line(ret = cmd.ExecuteNonQuery).Please find below code and assist how to fix the flaw..
string connectionString = ConfigurationSettings.AppSettings["ConnectionString"];
SqlConnection conn = new SqlConnection(connectionString);
try
{
SqlCommand cmd = new SqlCommand(strQuery, conn);
conn.Open();
ret = cmd.ExecuteNonQuery();
}
finally
{
if(conn != null)
{
conn.Close();
conn.Dispose();
}
}
return ret;