A potentially dangerous Request.Form value . . .

  •  06-16-2004, 12:07 PM

    A potentially dangerous Request.Form value . . .

    I get the following error when I try to submit my form.  I really don't want to set validateRequest=false.  Any ideas around this?

     

    A potentially dangerous Request.Form value was detected from the client (txtComment="this ia<BR>a test").

    Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.

    Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (txtComment="this ia<BR>a test").

    Source Error:

    An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.

    Stack Trace:

    [HttpRequestValidationException (0x80004005): A potentially dangerous Request.Form value was detected from the client (txtComment="this ia<BR>a test").]
       System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName)
       System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName)
       System.Web.HttpRequest.get_Form() +113
       System.Web.UI.Page.GetCollectionBasedOnMethod()
       System.Web.UI.Page.DeterminePostBackMode()
       System.Web.UI.Page.ProcessRequestMain()
       System.Web.UI.Page.ProcessRequest()
       System.Web.UI.Page.ProcessRequest(HttpContext context)
       System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
       System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
    


    Version Information: Microsoft .NET Framework Version:1.1.4322.573; ASP.NET Version:1.1.4322.573
View Complete Thread