过滤sql语句

#Region "过滤sql语句"
Public Shared Function denny(ByVal id) As String
id = Replace(id, "'", "")
id = Replace(id, " and ", "")
id = Replace(id, "select ", "")
id = Replace(id, "update ", "")
id = Replace(id, " chr ", "")
id = Replace(id, " delete ", "")
id = Replace(id, "%20from", "")
id = Replace(id, ";", "")
id = Replace(id, "insert ", "")
id = Replace(id, " mid ", "")
id = Replace(id, "set", "")
id = Replace(id, "chr(37)", "")
id = Replace(id, "=", "")
id = Replace(id, "(", "")
id = Replace(id, "exec%20master.dbo.xp_cmdshell", "")
id = Replace(id, "xp_cmdshell", "")
id = Replace(id, "net localgroup administrators", "")
Return id
End Function
#End Region

posted @ 2020-04-13 15:13  石衣_2014  阅读(315)  评论(0编辑  收藏  举报