. :
SQL=SQL.Replace("''","'");
SQL, , '' ' .
: :
SELECT * FROM tab WHERE col = '<input value goes here>'
, , :
SELECT * FROM tab WHERE col = ''
... SQL.Replace( "''", "'" ) :
SELECT * FROM tab WHERE col = '
, .
, SQL.Replace( "'", "' '" ), :
SELECT * FROM tab WHERE col = ''''
, col ( " , , " ). .
, - :
SQL = "SELECT * FROM tab WHERE col = '" & ParamValue.Replace("'", "''") & "'"
, , . , , , SQL stament.
, , , . MS SQL server QUOTED_IDENTIFIER , . , , , . , escape- ( ) !!
:
SET QUOTED_IDENTIFIER OFF
SELECT " "" '' "
:
" ''
, , , . , QUOTED_IDENTIFIER , . :
http://msdn.microsoft.com/en-us/library/ms174393.aspx