sql注入
摘要:
str = str.Replace("'", "''"); str = str.Replace(";", ""); str = str.Replace("%", "/%"); str = str.Replace("_", "/_"); return str; //string key = this.txt_Key_Name.Text.Trim(); //key = key.Replace("'", "''").Replace("%", "/%").Replace("_", "/_"); //strWhere.Append(" AND (REF_NAME like '%" + key + "%' 阅读全文