这个一般都是要通过转换字符的,如:
<%
function HTMLEncode(fString)
if not isnull(fString) then
fString = replace(fString, ">", "&gt;")
fString = replace(fString, "<", "&lt;")
fString = Replace(fString, " ", "&nbsp;")
fString = Replace(fString, CHR(32), "&nbsp;")
fString = Replace(fString, CHR(34), "&quot;")
fString = Replace(fString, CHR(39), "&#39;")
fString = Replace(fString, CHR(13), "")
fString = Replace(fString, CHR(10) &
CHR(10), "</P><P>")
fString = Replace(fString, CHR(10), "<BR>")
HTMLEncode = fString
end if
end function%>
<% MESS=[red]htmlencode([/red]REQUEST。FORM(“MEMO”)[red])[/red] %>
<% SQL1=” INSERT INTO TABLE (MESSAGE) VALUES(MESS)“ %>