A part of my code is subjected to SQL injection. Below is the code
public int Insert(string usrtest )
{
DataTable dt = new DataTable();
SqlConnection con = new SqlConnection(conn);
// SqlCommand cmd = new SqlCommand("select * from table where name=@name", con);
SqlDataAdapter adp = new SqlDataAdapter("select * from table where name=@name", con);
con.Open();
adp.SelectCommand.Parameters.AddWithValue("@name", usrtest );
adp.Fill(dt);
SqlCommand cmd1 = new SqlCommand("Update table set Date='" + DateTime.Now + "' where name='" + usrtest + "'", con);
cmd1.ExecuteNonQuery();
con.Close();
}