Rem 过滤特殊字符
Function FilterHtml(str)
Str=Trim(Str)
If IsNull(Str) Then
FilterHtml = ""
Exit Function
End If
Dim re
Set re=new RegExp
re.IgnoreCase =True
re.Global=True
re.Pattern="(\r\n){3,}"
Str=re.Replace(Str,"$1$1$1")
Set re=Nothing
Str = Replace(Str,"'","´")
'Str = Replace(Str,",",",")
Str = Replace(Str, "select", "select")
Str = Replace(Str, "join", "join")
Str = Replace(Str, "union", "union")
Str = Replace(Str, "where", "where")
Str = Replace(Str, "insert", "insert")
Str = Replace(Str, "delete", "delete")
Str = Replace(Str, "update", "update")
Str = Replace(Str, "like", "like")
Str = Replace(Str, "drop", "drop")
Str = Replace(Str, "create", "create")
Str = Replace(Str, "modify", "modify")
Str = Replace(Str, "rename", "rename")
Str = Replace(Str, "alter", "alter")
Str = Replace(Str, "cast", "cast")
FilterHtml = str
End Function
Function Rq(name)
'On Error Resume Next
IF Request.QueryString(name) = "" or isNull(Request.QueryString(name)) Then
Rq=""
Else
Dim i
For i= 1 to Request.QueryString(name).Count
Rq=Rq & Request.QueryString(name)(i)
Next
Rq=FilterHtml(Rq)
End If
End Function
Rem 获取Post传过来的项值,并将其过滤特殊字符
Function Rp(name)
IF Request.Form(name) = "" or isNull(Request.Form(name)) Then
Rp=""
Else
Rp=Request.Form(name)
Rp=FilterHtml(Rp)
End IF
End Function
Function R(ParaName,ParaType)
Dim Paravalue
Paravalue=Request(ParaName)
If ParaType=1 then
IF Not IsNumeric(Paravalue) or Paravalue = "" or isNull(Paravalue) Then
Paravalue = 0
Else
Paravalue = Paravalue
End IF
Else
Paravalue=FilterHtml(Paravalue)
End if
R=Paravalue
End function