public Function RSQL(strChar)
4 F5 c6 f1 A5 K4 |; M+ C If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
3 O$ q3 f6 u3 K8 T4 _ Dim strBadChar, arrBadChar, tempChar, I N; R3 s7 t7 m1 w) C
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的004 v4 {, u8 N2 @+ ~6 g4 d* u# A
arrBadChar = Split(strBadChar, ",")) r0 {7 P0 O$ F% W% Q
tempChar = strChar
# z) B. m; M* l; Q. D For I = 0 To UBound(arrBadChar)1 K, r. ], E* H4 k+ K2 W2 U
tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
4 T- B0 v% U* d$ A8 b Next
+ i% d) ?9 b9 \' P! d2 f0 F. z RSQL = tempChar9 p+ c- W) E; b. _* S N+ @3 ?
End Function& ^4 ~. u: |* ^# l
|