Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8090913
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 5, 20262026-06-05T19:53:03+00:00 2026-06-05T19:53:03+00:00

I am trying to check the security of my MVC application. When I try

  • 0

I am trying to check the security of my MVC application. When I try to input html or javascript it gives an error: Potential dangerous request.

Server Error in '/' Application.
A potentially dangerous Request.Form value was detected from the client (TEKST="<html><b>joo</b></ht...").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. To allow pages to override application request validation settings, set the requestValidationMode attribute in the httpRuntime configuration section to requestValidationMode="2.0". Example: <httpRuntime requestValidationMode="2.0" />. After setting this value, you can then disable request validation by setting validateRequest="false" in the Page directive or in the <pages> configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case. For more information, see http://go.microsoft.com/fwlink/?LinkId=153133.

Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (TEKST="<html><b>joo</b></ht...").

Source Error:

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.

This looks good, it is not possible to inject HTML or JavaScript. But the thing that I do not like, the users will see my version of ASP.net and everything.

How can I remove this error and give just a message with: I don’t like your input or whatever.

I have tried to do this but this is not working:

[Authorize]
public ActionResult Create(int album_id)
{
    ViewBag.album_id = album_id;
    return View();
}

[Authorize]
[HttpPost]
public ActionResult Create(REVIEW model)
{
    string txt = null;
    try
    {
        txt = model.TEKST;
    }
    catch (System.Web.HttpRequestValidationException)
    {
        txt = "errorrr";
    }


    return RedirectToAction("Add", new { tekst = txt, album_id=model.ALBUM_ID});
}

SOLUTION:
See Nudier’s answer

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-05T19:53:05+00:00Added an answer on June 5, 2026 at 7:53 pm

    you can handle errors within your application in the following way

    1. Setting the CustomErros mode section in your Web.Config file of your application

    This the lists of options the mode attribute can accept.

    RemoteOnly: Generic error pages are shown for remote users. Rich error pages are shown for
    local requests (requests that are made from the current computer). This is the
    default setting.

    Off: Rich error pages are shown for all users, regardless of the source of the request.
    This setting is helpful in many development scenarios but should not be used in
    a deployed application.

    On: Generic error pages are shown for all users, regardless of the source of the
    request. This is the most secure option.

         <System.Web>
          //map all the erros presented in the application to the error.aspx webpage
         <customErrors mode="RemoteOnly" defaultRedirect ="~/error.aspx" />
        <System.Web>
    

    2. throught Global.asax file in the Application_Error function

         //handle all the errors presented in the application
          void Application_Error(object sender, EventArgs e){  
         Server.Tranfer("error.aspx");
        }
    

    I hope this works for you.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I am trying to use spring security in my application developing restful web services
Can a security app check what servers(urls) is another app is trying to connect?
Trying to use security features and create Forms Authentication in my MVC3 application I
I am trying to add some security to my webpage. My webpage page.html has
I am trying to check a series of buttons to see if they have
I'm trying to check if a file exists. If I use this: NSData *data
I am trying to check the following and all throw an out of bounds
I'm trying to check a checkbox, i've tried doing the following :- $('#someId').attr('checked','checked'); $('#someId').attr('checked',
I am trying to check if an email address already exists in a user
I'm trying to check network available or not. But in my emulator it always

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.