public Function RSQL(strChar)& D; v, |- \) W1 M) M. Q4 Y
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
/ @3 m& ~ p Z. I0 } Dim strBadChar, arrBadChar, tempChar, I3 ?6 E* m$ ^1 R, k
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00& q; N7 | P- |% X
arrBadChar = Split(strBadChar, ",")& {& D- `' c9 `" z0 J$ M+ E
tempChar = strChar
m4 c1 s8 A5 T4 C, k For I = 0 To UBound(arrBadChar)
" ]. e; u( Z5 f1 J0 ^ tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空, \& t; J! a6 i
Next$ p' ~7 e" i* m( V+ B( Q
RSQL = tempChar
- q2 ~0 G' b$ _. g$ OEnd Function$ X- H! e9 R% k
|