dangerous request.form in cuteeditor v6.6

  •  01-15-2011, 8:57 AM

    dangerous request.form in cuteeditor v6.6

    running cutesoft editor in our production environment, running IIS7 app is asp.net v4.0
     
    In my web.config I have the following set
     
    <pages validateRequest="false" enableEventValidation="false" controlRenderingCompatibilityVersion="3.5" clientIDMode="AutoID">
     
     
    but am still getting this error, please advise
     
     

    Error Report for /FISDOnline(PRODUCTION1). This is a production issue.


    A potentially dangerous Request.Form value was detected from the client (CurrentText="

    ...").

    Description: A validation error has occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

    Exception Details: System.Web.HttpRequestValid

    Source Error:

    [No relevant source lines]


    Source File: N/A    Line: N/A

    Stack Trace:

       at System.Web.HttpRequest.ValidateString(String value, String collectionKey, RequestValidationSource requestCollection)
       at System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, RequestValidationSource requestCollection)
       at System.Web.HttpRequest.get_Form()
       at System.Web.HttpRequest.get_HasForm()
       at System.Web.UI.Page.GetCollectionBasedOnMethod(Boolean dontReturnNull)
       at System.Web.UI.Page.DeterminePostBackMode()
       at System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint)
       at System.Web.UI.Page.ProcessRequest(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint)
       at System.Web.UI.Page.ProcessRequest()
       at System.Web.UI.Page.ProcessRequestWithNoAssert(HttpContext context)
       at System.Web.UI.Page.ProcessRequest(HttpContext context)
       at ASP.PopUpSpell.ProcessRequest(HttpContext context)
       at System.Web.HttpApplication.CallHandlerExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()
       at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)



    Event Information:

    Event code: 3003 Event message: A validation error has occurred. Event time: 1/15/2011 12:02:07 AM Event time (UTC): 1/15/2011 5:02:07 AM Event ID: 48e376b6feed4dd0aacc79d55cedfc7e Event sequence: 831 Event occurrence: 2 Event detail code: 0 Application information: Application domain: /LM/W3SVC/4/ROOT-1-129395328264068696 Trust level: Full Application Virtual Path: / Application Path: D:\_Webpages\_canned\it_ajax_net2_PUB\ Machine name: PRODUCTION1 Process information: Process ID: 5296 Process name: w3wp.exe Account name: NT AUTHORITY\NETWORK SERVICE Exception information: Exception type: System.Web.HttpRequestValidationException Exception message: A potentially dangerous Request.Form value was detected from the client (CurrentText="

    ..."). Request information: Request URL: https://secure.incident-tracker.com:443/CuteSoft_Client/CuteEditor/SpellCheck.aspx?Culture=en-US Request path: /CuteSoft_Client/CuteEditor/SpellCheck.aspx User host address: 199.184.205.92 User: Is authenticated: False Authentication Type: Thread account name: NT AUTHORITY\NETWORK SERVICE Thread information: Thread ID: 15 Thread account name: NT AUTHORITY\NETWORK SERVICE Is impersonating: False Stack trace: at System.Web.HttpRequest.ValidateString(String value, String collectionKey, RequestValidationSource requestCollection) at System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, RequestValidationSource requestCollection) at System.Web.HttpRequest.get_Form() at System.Web.HttpRequest.get_HasForm() at System.Web.UI.Page.GetCollectionBasedOnMethod(Boolean dontReturnNull) at System.Web.UI.Page.DeterminePostBackMode() at System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) at System.Web.UI.Page.ProcessRequest(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) at System.Web.UI.Page.ProcessRequest() at System.Web.UI.Page.ProcessRequestWithNoAssert(HttpContext context) at System.Web.UI.Page.ProcessRequest(HttpContext context) at ASP.PopUpSpell.ProcessRequest(HttpContext context) at System.Web.HttpApplication.CallHandlerExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute() at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)

View Complete Thread