//3.获取数据库操作对象
stmt = conn.createStatement();
//4.执行sql
//存在sql注入问题
//假如此时userName="张三",userPwd="张三'or'1'='1"
//通过字符串拼接将sql关键字or拼接进去
//String sql="select * from user where name='张三' and pwd ='张三'or'1'='1'"
//不需要正确的用户名及密码就能此时就能进入系统
String sql = "select * from user where name='"+userName+"'and pwd ='"+userPwd+"'";