asp.net 2005 替换SQL危险字符
public string replaceStr(string inputString)
{
string replaceIn = "'|;|and|(|)|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare|or|and|" + ((char)9).ToString() + "|" + ((char)34).ToString() + "|" + ((char)32).ToString() + "|" + ((char)39).ToString();
string[] ArrayReplaceIn = replaceIn.Split(char.Parse("|"));
int i;
for (i = 0; i < ArrayReplaceIn.Length; i++)
{
inputString = inputString.Replace(ArrayReplaceIn[i].ToString(),"");
}
return inputString;
}