Bugs item #1560055, was opened at 2006-09-17 08:08
Message generated for change (Tracker Item Submitted) made by Item Submitter
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=784889&aid=1560055&group_id=152364
Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: UI
Group: Confirmed Bug
Status: Open
Resolution: None
Priority: 5
Submitted By: Si (tectsoft)
Assigned to: Si (tectsoft)
Summary: Not allowed to use HTML in Board Settings (Admin Only)
Initial Comment:
A potentially dangerous Request.Form value was
detected from the client
(Settings1:txtBoardTitle="FBTalk<BR><img src="img/fb...").
Description: Request Validation has detected a
potentially dangerous client input value, and
processing of the request has been aborted. This value
may indicate an attempt to compromise the security of
your application, such as a cross-site scripting
attack. You can disable request validation by setting
validateRequest=false in the Page directive or in the
configuration section. However, it is strongly
recommended that your application explicitly check all
inputs in this case.
Exception Details:
System.Web.HttpRequestValidationException: A
potentially dangerous Request.Form value was detected
from the client
(Settings1:txtBoardTitle="FBTalk<BR><img src="img/fb...").
Source Error:
An unhandled exception was generated during the
execution of the current web request. Information
regarding the origin and location of the exception can
be identified using the exception stack trace below.
Stack Trace:
[HttpRequestValidationException (0x80004005): A
potentially dangerous Request.Form value was detected
from the client
(Settings1:txtBoardTitle="FBTalk<BR><img src="img/fb...").]
System.Web.HttpRequest.ValidateString(String s,
String valueName, String collectionName) +240
System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection
nvc, String collectionName) +99
System.Web.HttpRequest.get_Form() +113
System.Web.UI.Page.GetCollectionBasedOnMethod() +69
System.Web.UI.Page.DeterminePostBackMode() +128
System.Web.UI.Page.ProcessRequestMain() +2112
System.Web.UI.Page.ProcessRequest() +218
System.Web.UI.Page.ProcessRequest(HttpContext
context) +18
System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute()
+179
System.Web.HttpApplication.ExecuteStep(IExecutionStep
step, Boolean& completedSynchronously) +87
----------------------------------------------------------------------
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=784889&aid=1560055&group_id=152364
|