//Encode the strings to safe characters // call class by using SqlEncode(yourInsertValue) public string SqlEncode(string inStr) { inStr = inStr.Replace("'", "'"); inStr = System.Security.SecurityElement.Escape(inStr); inStr = HttpContext.Current.Server.HtmlEncode(inStr); return inStr; }
//decode the string public string SqlDecode(string inStr) { if (inStr == "") return null; inStr = HttpContext.Current.Server.HtmlDecode(inStr); inStr = inStr.Replace("'", "'"); return inStr; }