public Function RSQL(strChar)0 |1 r" {$ d+ N8 w4 m" E
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
" `9 h! r" V1 A% W. U- p# I, I7 C, ? Dim strBadChar, arrBadChar, tempChar, I6 |8 Q* M$ W* Q m0 v
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00
7 U; |& p% ~8 W! n' o3 t8 s) b% V arrBadChar = Split(strBadChar, ",")
5 U7 A+ m% k. |# v3 v9 K tempChar = strChar
9 X; U: N* i/ Y$ O( {" V For I = 0 To UBound(arrBadChar)
. ^. A7 s: E O8 ]6 h: y9 k tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空7 M. E' p7 P8 |; [9 t" P# W( ], t' B% S
Next* l- b, U. `" r
RSQL = tempChar
& R! V# k; }6 IEnd Function
+ \; u- o5 y' u( n, r" N+ K |