C#使用sql查询语句求解

sing System;
using System.Data;
using System.Data.SqlClient;
using System.Collections.Generic;
using System.Linq;
using System.Windows.Forms;

namespace library
{
class linksql
{
public void con(string shuming)
{

string connString;
connString = "Data Source=DESKTOP-MPLGIDU\SQLEXPRESS;uid=sa;pwd=admin;database=book;";
SqlConnection sConn = new SqlConnection(connString);
try
{
sConn.Open();
}
catch (Exception ex)
{
Console.WriteLine("连接错误:" + ex.Message);
}
string sql;
sql = "declare @cry varchar(20) set @cry=shuming select * from book1 where 书名=@cry";

SqlCommand sCmd = new SqlCommand(sql, sConn);
SqlDataReader sdr = null;

sdr = sCmd.ExecuteReader();

while (sdr.Read())
{
Console.WriteLine(sdr[0] + " " + sdr["书名"] + sdr["作者"] + " " + sdr["索书号"]);
}
sdr.Close();
sConn.Close();
}

}
}

sql = "declare @cry varchar(20) set @cry=shuming select * from book1 where 书名=@cry";
换成
sql = "select * from book1 where 书名='" + shuming + "'";

sql = "declare @cry varchar(20) ; set @cry=shuming ;select * from book1 where 书名=@cry"; 加分号