1,PreparedStatement/Statement区别: 1,防止sql注入式攻击(sql注入:就是通过非正常手段(比如在url中添加参数)),将sql文执行(比如or 1=1)
2,PreparedStatement的executexxx()没有参数,有参数的都是Statement的executexxx()
3,尽量选择PreparedStatement方式,同时尽量通过?来传参而不要拼接字符串
2,java.sql.Date/java.util.Date java.sql.DateD继承自java.util.Date Date date = new Date(); System.out.println("sql = " + new java.sql.Date(date.getTime())); // sql = 2017-02-24 System.out.println("util = " + new java.util.Date(date.getTime()));// util = Fri Feb 24 14:16:19 CST 2017