Tuesday, June 30, 2009

A potentially dangerous Request.Cookies value was detected from the client

A potentially dangerous Request.Cookies value was detected from the client (AppEvtStat="Deal...").

Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.

To resolve this:
Add validateRequest="false" on the Page element like below

<%@ Page validateRequest="false" %>

Reference: here

No comments: