A potentially dangerous Request.QueryString value was detected from the client 的解决办法

本文介绍了当使用QueryString接收特定特殊字符时出现的安全验证错误,并提供了禁用验证的解决方案。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

今天遇到一个问题,没见过。

用QueryString 去接受 字符串“☞☞”时出错了,直接崩了。

显示

A potentially dangerous Request.QueryString value was detected from the client (title="☞☞&#9758...").

Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.

Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.QueryString value was detected from the client (title="☞☞&#9758...").

Source Error:

[No relevant source lines]

Source File: c:/windows/Microsoft.NET/Framework/v2.0.50727/Temporary ASP.NET Files/root/8046b68d/14bc268/App_Web_7uz1szh1.0.cs    Line: 0

Stack Trace:

[HttpRequestValidationException (0x80004005): A potentially dangerous Request.QueryString value was detected from the client (title="☞☞&#9758...").]
   System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName) +8721914
   System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName) +111
   System.Web.HttpRequest.get_QueryString() +129
   System.Web.UI.Page.GetCollectionBasedOnMethod(Boolean dontReturnNull) +65
   System.Web.UI.Page.DeterminePostBackMode() +63
   System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +6785
   System.Web.UI.Page.ProcessRequest(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +242
   System.Web.UI.Page.ProcessRequest() +80

 

原因:

Microsoft .NET Framework 1.1 causes this due to enhanced security features (request validation).  Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted.  This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack.  You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section of Web.config.  However, it is strongly recommended that your application explicitly check all inputs in this case.

 

 

网上搜了搜发现解决办法。

Set the value of validateRequest attribute of pages element to false.

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值