public Function RSQL(strChar)
% N% c6 L U% r6 q+ k If strChar = "" or IsNull(strChar) Then RSQL = "":Exit Function8 ^/ h% O; ~' t; b8 r
Dim strBadChar, arrBadChar, tempChar, I8 v3 t% K6 Q( ^0 X" x! M
strBadChar = "$,#,',%,^,&,?,(,),<,>,[,],{,},/,\,;,:," & Chr(34) & "," & Chr(0) & ""’注意这里过滤的是特殊字符 ‘Chr(34)对应的ASCII码是双引号。Chr(0)其实就是我们上传改包把空格(20)改成的00
- y: [/ Z# K" {# s+ { arrBadChar = Split(strBadChar, ",") o9 h7 p6 j1 t, Z E5 J5 Z
tempChar = strChar# s" ?# P9 |' H
For I = 0 To UBound(arrBadChar)
j1 v- \2 M/ I$ L6 F& k$ O tempChar = Replace(tempChar, arrBadChar(I), "") ‘将特殊字符过滤为空3 t1 F2 g+ ?2 t* ?/ U3 c; b
Next8 o s o! ~2 B
RSQL = tempChar
9 t' k1 `9 H1 X2 {, j3 ^0 `End Function
& ~8 S8 E! ]# u, Q |