codice:
'IllegalChars funzione di guardia contro SQL injection
Function IllegalChars(sInput)
'Dichiara le variabili
Dim iCounter, SBadChars
'Set IllegalChars a False
IllegalChars = False
'Crea un array di caratteri illegali e parole
sBadChars = array ("select", "drop", ",", "-", "isert", "delete", "xp_", "_", "#", "%", "&", "'", "(", ")", "/", "\", ":", ",", "<", ">", "= "," [","] "," "," `", "|?", "__ ")
'Loop attraverso sBadChars array utilizzando il nostro contatore e funzione UBound
For iCounter = 0 to UBound (sBadChars)
'Usare funzione InStr per verificare la presenza di carattere illegale nella nostra variabile
If Instr (sInput, sBadChars (iCounter))> 0 Then
IllegalChars = True
End If
Next
End Function