public Function RSQL(strChar)
" M( B3 J' N! F! o If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
& x& j; u7 L5 O2 `3 L. }0 l Dim strBadChar, arrBadChar, tempChar, I( Z! D9 t1 X& D2 S
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的000 j$ k" x1 E5 t! o
arrBadChar = Split(strBadChar, ",")2 q5 D2 n T; l1 k8 N) |/ w# K
tempChar = strChar2 w2 ]3 Q: N$ F4 c6 t6 j5 Z
For I = 0 To UBound(arrBadChar)8 a1 x6 R# y0 \) n% a, `# J
tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
, W3 z; R2 z; \8 h L6 C Next
! \5 I) g) K5 Q RSQL = tempChar: n2 n" ?5 i+ Z/ a, ?. H2 B
End Function* T& u" D/ S8 o# M. K! m
|