解決方案:沒有指定參數
String user = req.getParameter("user");
String pwd = req.getParameter("pwd");
Connection conn = DbUtil.getCon();
String sql = "select name from user where name=? and password=?";
PreparedStatement pst = conn.prepareStatement(sql);
pst.setString(1, user); pst.setString(2, pwd);
