Dict.CN 在线词典, 英语学习, 在线翻译 ------------- MyGitee 朱秋贵内科诊所 My腾云code

过滤sql匹配符号 防止sql注入

/// <summary> /// 过滤sql中非法字符
        
/// </summary>
       
/// <param name="value">要过滤的字符串 </param>
       
/// <returns>string </returns>
        public static string Filter(string value)
        {
           
if (string.IsNullOrEmpty(value)) return string.Empty;
            value
= Regex.Replace(value, @";", string.Empty);
            value
= Regex.Replace(value, @"'", string.Empty);
            value
= Regex.Replace(value, @"&", string.Empty);
            value
= Regex.Replace(value, @"%20", string.Empty);
            value
= Regex.Replace(value, @"--", string.Empty);
            value
= Regex.Replace(value, @"==", string.Empty);
            value
= Regex.Replace(value, @" <", string.Empty);
            value
= Regex.Replace(value, @">", string.Empty);
            value
= Regex.Replace(value, @"%", string.Empty);

           
return value;
        }
posted @ 2009-11-26 08:57  cn2024  阅读(341)  评论(0编辑  收藏  举报