public Function RSQL(strChar)' T$ d9 d; J/ ?
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function8 j6 z0 H5 y1 {) R7 O
Dim strBadChar, arrBadChar, tempChar, I/ q6 L. F# j/ o7 a% F
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00- P: @. g) F: _
arrBadChar = Split(strBadChar, ",")
- k5 {4 W! l2 d m3 S* x tempChar = strChar
% I8 ~' S s& ^( W. r [! C For I = 0 To UBound(arrBadChar)
) C! l7 M ]3 ?4 x; q: U, H tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空 x8 w' d: m1 G5 R1 u) }2 Z1 q
Next
7 T" l) Q! ], n: d! w1 G/ \ RSQL = tempChar$ e- X8 w5 Z. u
End Function4 F+ U8 f& f U
|