public Function RSQL(strChar)9 r+ K* I/ Q E1 a; O; U4 R1 l
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
; ?7 D9 o7 l( P. \ Dim strBadChar, arrBadChar, tempChar, I6 Y, c( [) l6 N: j q$ Y- k
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00, V3 y) [3 z7 g. Q% `1 a
arrBadChar = Split(strBadChar, ",")5 ^2 z0 D1 i/ S6 `6 n
tempChar = strChar
R6 Q- _; j$ @: ~- s. R For I = 0 To UBound(arrBadChar)* E+ _2 _% L Q3 p$ s
tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
1 K0 F/ } X7 l8 ]/ `7 P Next% e1 H2 C* F( U# {! M
RSQL = tempChar1 `' B9 U! }8 F+ a2 f8 n0 q
End Function% u$ G4 |4 d+ Y
|