![](https://cos-cdn.shuashuati.com/pipixue-web/2020-1231-2005-12/ti_inject-812ce.png)
设数据表user中存储了两个字符串型的字段“name”、“pwd”,分别表示用户名和密码,则以下那条sql语句可以正确判断用户的合法性( )
A.
select * from user where name=$name and pwd=$pwd
B.
select * from user where name= '$name ' and pwd= '$pwd '
C.
insert into user (name , pwd) values ('$name ' , '$pwd ')
D.
update user set name= '$name, pwd=$pwd '