public Function RSQL(strChar)4 ~' h/ E( d1 U4 [$ ~ \' P& u
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
$ L" M/ ?4 {% D/ _ Dim strBadChar, arrBadChar, tempChar, I/ J( F* ?/ Y6 |# ^
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00+ t6 E4 c5 t! u$ q- k/ x
arrBadChar = Split(strBadChar, ",")
( s. z8 m" w; U7 ?9 b tempChar = strChar
% V$ g6 Y; F0 ~" e1 |" Q" h ^ For I = 0 To UBound(arrBadChar)1 @6 T( q% H* o; M: K8 X; M$ X
tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空 q7 @2 j" T: X2 j% Y9 K
Next
' X: ^+ A$ H6 y/ O RSQL = tempChar
6 O9 O; V0 L2 b" H0 ZEnd Function1 k9 M. Z: d/ V" @5 K* ?: F' Q# W
|