防SQL注入函数

  void Check()
    {
      
        string sql_injdata = "and|exec|insert|select|delete|update|count|chr|mid|master|truncate|char|declare";//要过虑的关键字
        string[] SQL_inj = sql_injdata.Split('|');
        string b;
        string a1;
        string[] a = new string[32];
        int bj = 0;

        //a[0] = txtMainTypePrecent.Text;//要检查的控件
        //a[1] = txtSecondTypePrecent.Text;
        a[0] = txtWorkContent1.Text;
        //a[3] = txtSpendTimeForContent1.Value;
        //a[4] = txtPrecentForContent1.Text;
        a[1] = txtWorkContent2.Text;
        //a[6] = txtSpendTimeForContent2.Value;
        //a[7] = txtPrecentForContent2.Text;
        a[2] = txtWorkContent3.Text;
        //a[9] = txtSpendTimeForContent3.Value;
        //a[10] = txtPrecentForContent3.Text;
        a[3] = txtWorkContent4.Text;
        //a[12] = txtSpendTimeForContent4.Value;
        //a[13] = txtPrecentForContent4.Text;
        a[4] = txtWorkContent5.Text;
        //a[15] = txtSpendTimeForContent5.Value;
        //a[16] = txtPrecentForContent5.Text;
        a[5] = txtGanYan1.Text;
        a[6] = txtGanYan2.Text;
        a[7] = txtGanYan3.Text;
        a[8] = txtAdviceForChange1.Text;
        a[9] = txtAdviceForChange2.Text;
        a[10] = txtAdviceForChange3.Text;
        a[11] = txtSatisfied1.Text;
        a[12] = txtSatisfied2.Text;
        a[13] = txtSatisfied3.Text;
        a[14] = txtUNAccessories1.Text;
        a[15] = txtUNAccessories2.Text;
        a[16] = txtUNAccessories3.Text;
        a[17] = txtUNAccessories5.Text;
        a[18] = txtUNAccessories6.Text;
        a[19] = txtUNAccessories7.Text;
        a[20] = txtUNAccessories8.Text;
        a[21] = txtUNAccessories4.Text;
        a[22] = txtAdvice1.Text;
        a[23] = txtAdvice2.Text;
        a[24] = txtAdvice3.Text;
        a[25] = txtSayToPrincipal.Text;
        a[26] = txtSayToLeader.Text;
        a[27] = txtAdvice4.Text;
        a[28] = txtAdvice5.Text;
        a[29] = txtAdvice6.Text;
        a[30] = txtAdvice7.Text;
        a[31] = txtAdvice8.Text;

        for (int i = 0; i < SQL_inj.Length; i++)
        {
            b = SQL_inj[i];

            for (int j = 0; j < a.Length; j++)
            {
                a1 = a[j];
                if (a1.IndexOf(b) > -1)
                {
                    bj = -1;
                   
                    break;
                }
            }


            if (bj == -1)
            {
                Response.Write("<script>alert('系统提示:请不要在输入框中包含非法字符!!!');</script>");
                return;
                break;
            }

        }

    }

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 2
    评论
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值