public Function RSQL(strChar)+ q; Q5 B8 Z; Y# W7 C- u
If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function5 U- M0 [; U* m2 q) |0 I! o: `
Dim strBadChar, arrBadChar, tempChar, I
2 }2 w5 L0 x5 g: w strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00
* S( S& M& |) \: U! p) d) Q( ` arrBadChar = Split(strBadChar, ",")2 y9 L9 K% y ^- F, g
tempChar = strChar! t" P3 a: d& e$ J* P
For I = 0 To UBound(arrBadChar)' G4 z* A# ]; ?' y% I4 O" J; t' u
tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空
) ^: x/ b) J' R Next/ @0 t7 O, o5 A7 e
RSQL = tempChar
2 q, f5 V/ k$ M% v' Q+ OEnd Function
. y* r8 g# S: a4 b- P |