美文网首页
【C#】过滤Sql语句非法字符串

【C#】过滤Sql语句非法字符串

作者: KevinTseng | 来源:发表于2018-06-12 19:56 被阅读0次
过滤Sql语句非法字符串
/// <summary>
/// 过滤SQL非法字符串
/// </summary>
/// <param name="value"></param>
/// <returns></returns>
public static string GetSafeSQL(string value)
{
    if (string.IsNullOrEmpty(value))
        return string.Empty;
    value = Regex.Replace(value, @";", string.Empty);
    value = Regex.Replace(value, @"'", string.Empty);
    value = Regex.Replace(value, @"&", string.Empty);
    value = Regex.Replace(value, @"%20", string.Empty);
    value = Regex.Replace(value, @"--", string.Empty);
    value = Regex.Replace(value, @"==", string.Empty);
    value = Regex.Replace(value, @"<", string.Empty);
    value = Regex.Replace(value, @">", string.Empty);
    value = Regex.Replace(value, @"%", string.Empty);
    return value;
}  

相关文章

网友评论

      本文标题:【C#】过滤Sql语句非法字符串

      本文链接:https://www.haomeiwen.com/subject/iwbreftx.html