public Function RSQL(strChar)
" m# i7 E4 ^% g% r If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function3 Z3 F7 H! h! g% O
Dim strBadChar, arrBadChar, tempChar, I' A. [6 ]% |. H* w8 ^; O! {* z
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00
- n( d4 Z9 c! o# b* G6 J) G4 z arrBadChar = Split(strBadChar, ",")* B C4 G$ i+ n3 G# [# d0 n
tempChar = strChar
. @5 R( s3 m* a5 M For I = 0 To UBound(arrBadChar)
" {" k" g% M# K' V) S tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
' ?7 V, f0 B' ^+ S/ ~ Next: ?* d2 k) b: I6 B& ?$ S
RSQL = tempChar1 Q" u% K3 x0 _; u3 M& l$ V; T3 h
End Function
" g7 ]- E- S0 Y& K7 K) G) w |