将字符串安全转换成可安全合成SQL语句的值
2015-01-13来源:易贤网

将字符串安全转换成可安全合成SQL语句的值:

public static string dfStrToSQL(string str)

{

str = str.ToLower();

str = str.Replace("'", "''");

str = str.Replace(";--", "");

str = str.Replace("select", "");

str = str.Replace(" or ", "");

str = str.Replace(" and ", "");

str = str.Replace("insert", "");

str = str.Replace("update", "");

str = str.Replace("delete", "");

str = str.Replace("from", "");

str = str.Replace("exec master", "");

str = str.Replace("group administrators", "");

str = str.Replace("xp_cmdshell", "");

str = str.Replace("drop table", "");

str = str.Replace("truncate", "");

return str;

}

更多信息请查看IT技术专栏

推荐信息