public Function RSQL(strChar)( e8 H; Z e5 m/ F" w% C: M
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
5 `1 S. O& P1 D6 ?( i Dim strBadChar, arrBadChar, tempChar, I+ `" V4 r( ]7 t$ L, y2 G
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00" ^" k: K+ E6 i3 w9 f0 b5 c. I
arrBadChar = Split(strBadChar, ",")
- \3 M' e2 ~4 b9 L: N! D8 I tempChar = strChar' q/ [% o( n1 Y M% O
For I = 0 To UBound(arrBadChar)
0 Z' m" M: j- C/ s f tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
+ ?0 u0 h' p* c6 u! ` Next
V3 Y* I( c7 w, |0 B RSQL = tempChar5 V) h: p8 w) ?1 B
End Function
1 z1 D6 U4 H; K. H1 J2 [! m, n |