过滤sql匹配符号 防止sql注入

        ///  <summary> /// 过滤sql中非法字符
        
///  </summary>
       
///  <param name="value">要过滤的字符串 </param>
       
///  <returns>string </returns>
        public static string Filter(string value)
        {
           
if (string.IsNullOrEmpty(value)) return string.Empty;
            value
= Regex.Replace(value, @";", string.Empty);
            value
= Regex.Replace(value, @"'", string.Empty);
            value
= Regex.Replace(value, @"&", string.Empty);
            value
= Regex.Replace(value, @"%20", string.Empty);
            value
= Regex.Replace(value, @"--", string.Empty);
            value
= Regex.Replace(value, @"==", string.Empty);
            value
= Regex.Replace(value, @" <", string.Empty);
            value
= Regex.Replace(value, @">", string.Empty);
            value
= Regex.Replace(value, @"%", string.Empty);

           
return value;
        }

posted @ 2008-05-22 09:02  西门啥都吹  阅读(1108)  评论(0编辑  收藏  举报