public Function RSQL(strChar). x7 C' D1 L& E( T" T
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function
" B. q) O( V7 b/ t2 k3 Z+ ^6 U' u7 o Dim strBadChar, arrBadChar, tempChar, I7 A/ j% |% ~' \ p# l# C- i- ^
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00
9 x* d# s$ |8 C5 n. Q- D0 x3 @ arrBadChar = Split(strBadChar, ",")
' J$ Y3 E; G2 z- M- _ tempChar = strChar
. ?0 U* B7 P& J1 F For I = 0 To UBound(arrBadChar)
5 |3 v, U% F0 [7 {+ N tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
2 G l% T+ ?9 N! D# z Next
+ k2 C1 k P( M9 d+ y4 M RSQL = tempChar4 s- L' B- O7 j; i) v7 L: r
End Function
4 y8 G/ l3 I# s+ c- B! ~ |