//sql预处理对象
PreparedStatementpst=null;
pst=connection.prepareStatement(sql);
for(int i =0 ;I<pst.lenth;i++){
pst.setObject(i+1,pars[i]);
}
rs =pst.executeQuery();
pst.executeUpdate()
获取session对象
HttpSession session=request.getSession();
session赋值
session.setAttribute("newsUser",newsUser);
session获取
${newsUser}