public Function RSQL(strChar)
Y6 S; b$ m4 C7 j9 Z If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function; g% N8 w* d& G' K) \' T+ x1 p0 R2 J
Dim strBadChar, arrBadChar, tempChar, I9 }$ p' S) j' @! [2 r) A2 G! y
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00: \) M1 Z$ J1 c7 A5 B
arrBadChar = Split(strBadChar, ",")7 B! a! V% O; L: f* Q/ T) Q: u
tempChar = strChar
: k1 w: J4 D" U+ C, J For I = 0 To UBound(arrBadChar)
/ w, c8 p- M8 g* A8 e* `+ L tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
& e- T0 L) Y' w+ @5 g; q Next3 [& D+ l% {0 q! ], h! a
RSQL = tempChar+ o' K' A4 C& q% l7 p0 |* i: C
End Function
* L, ]' a! A ]1 Y. B% P- y% ` |