今天遇到一个问题,没见过。
用QueryString 去接受 字符串“☞☞”时出错了,直接崩了。
显示
A potentially dangerous Request.QueryString value was detected from the client (title="☞☞☞...").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.
Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.QueryString value was detected from the client (title="☞☞☞...").
Source Error:
[No relevant source lines]
Source File: c:/windows/Microsoft.NET/Framework/v2.0.50727/Temporary ASP.NET Files/root/8046b68d/14bc268/App_Web_7uz1szh1.0.cs Line: 0
Stack Trace:
[HttpRequestValidationException (0x80004005): A potentially dangerous Request.QueryString value was detected from the client (title="☞☞☞...").]
System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName) +8721914
System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName) +111
System.Web.HttpRequest.get_QueryString() +129
System.Web.UI.Page.GetCollectionBasedOnMethod(Boolean dontReturnNull) +65
System.Web.UI.Page.DeterminePostBackMode() +63
System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +6785
System.Web.UI.Page.ProcessRequest(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +242
System.Web.UI.Page.ProcessRequest() +80
原因:
Microsoft .NET Framework 1.1 causes this due to enhanced security features (request validation). Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section of Web.config. However, it is strongly recommended that your application explicitly check all inputs in this case.
网上搜了搜发现解决办法。
Set the value of validateRequest attribute of pages element to false.