dvnews里这行为什么要删除
1在dvnews里<pages validateRequest="false" />这行为什么在.net SDK 1.0及以前版本下使用dvnews时要删除,他到底起什么样的作用,
2.而我使用一个<asp:radiobuttonlist id="RadioButtonList1" runat="server" Width="102px" Height="15px" RepeatDirection="Horizontal" RepeatColumns="11">
<asp:ListItem Value="<img src="img\e0.gif"/>" Selected="True"><img src="img\e0.gif"/></asp:ListItem>
<asp:ListItem Value="<img src="img\e1.gif"/>"><img src="img\e1.gif"/></asp:ListItem>
......省略......
</asp:radiobuttonlist>
我的环境是.net sdk1.1,他报错:
A potentially dangerous Request.Form value was detected from the client (RadioButtonList1="<img src="img\e0.gif...").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.
Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (RadioButtonList1="<img src="img\e0.gif...").
Source Error:
An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.
Stack Trace:
[HttpRequestValidationException (0x80004005): A potentially dangerous Request.Form value was detected from the client (RadioButtonList1="<img src="img\e0.gif...").]
System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName) +230
System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName) +99
System.Web.HttpRequest.get_Form() +121
System.Web.UI.Page.GetCollectionBasedOnMethod() +70
System.Web.UI.Page.DeterminePostBackMode() +47
System.Web.UI.Page.ProcessRequestMain() +2106
System.Web.UI.Page.ProcessRequest() +217
System.Web.UI.Page.ProcessRequest(HttpContext context) +18
System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute() +179
System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously) +87
当我在webconfig里加入上面那行<system>...<pages validateRequest="false" />...</system>就正常了,这是怎么回事情,谢谢各位了