网站制作学习网ASP→正文:防sql注入函数
字体:

防sql注入函数

ASP 2008/5/19 14:36:27  点击:不统计

关键词:防sql注入函数,防sql注入,sql注入函数,防sql注入代码

reString是原来的字符串,HTMLEncode是转换后的字符串

Function HTMLEncode(reString)

Dim Str:Str=reString

If Not IsNull(Trim(Str)) Then

Str = Replace(Str, "&", "&")

Str = Replace(Str, ">", ">")

Str = Replace(Str, "<", "&lt;")

Str = Replace(Str, CHR(34),"&quot;")

Str = Replace(Str, CHR(39),"&#39;")

Str = Replace(Str, CHR(13), "")

Str = Replace(Str, " ", "&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, " ", "&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, " ", "&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, " ", "&nbsp;&nbsp;&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, " ", "&nbsp;&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, " ", "&nbsp;&nbsp;", 1, -1, 1)

Str = Replace(Str, CHR(10), "<br>")

Str = Replace(Str, "sel&#101;ct", "select")

Str = Replace(Str, "jo&#105;n", "join")

Str = Replace(Str, "un&#105;on", "union")

Str = Replace(Str, "wh&#101;re", "where")

Str = Replace(Str, "ins&#101;rt", "insert")

Str = Replace(Str, "del&#101;te", "delete")

Str = Replace(Str, "up&#100;ate", "update")

Str = Replace(Str, "lik&#101;", "like")

Str = Replace(Str, "dro&#112;", "drop")

Str = Replace(Str, "cr&#101;ate", "create")

Str = Replace(Str, "mod&#105;fy", "modify")

Str = Replace(Str, "ren&#097;me", "rename")

Str = Replace(Str, "alt&#101;r", "alter")

Str = Replace(Str, "ca&#115;t", "cast")

HTMLEncode=Str

end if

End Function

·上一篇:ASPJSCMSjava交流群 >>    ·下一篇:判断网址是否存在 >>
推荐文章
最新文章