Get the App
SLTechnology News&Howtos  ›  Network Security  › 

A potentially dangerous Request.Form value was detected from the client

Shulou Source: shulou.com Published: 2022-06-01 07:11:44 10月03日 Update

Some website programs choose net2.0 home page access normal background operation to report net version error, select net4.0 home page access report net version error, but the background operation is normal

Modify the web.config configuration file of the website program

Two lines circled

When a user submits a form to the server on a page, the server detects some potential input risks, such as content edited with rich text editor controls (RichTextBox, FreeTextBox, CuteEditor, etc.) that contains HTML tags or script tags, and the ASP.NET page throws a "A potentially dangerous Request.Form value was deceted from the client" exception. This is a protection mechanism for ASP.NET pages against page injection. To remove this protection, it is common practice to add the ValidateRequest= "false" attribute to the .aspx file. But starting with .NET 4.0, you may need to modify one more place to add this line of configuration to the website's web.config file:

At the same time, you also need to make sure that the user-typed part of the page does not have any code that injects *. It is common practice to use Encode processing.

Tags: Pages files websites practices backend servers tags versions users programs parts errors home page protection services input selection configuration code content Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux NVidia Microsoft Apple vpn