Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...dangerous Request.QueryStringdangerous Request.QueryString
Previous
 
Next
New Post
12/22/2010 1:17 PM
 

I have been working with a local copy of DNN 5.6.0 on a customers site. When accessing a standard page from DNN, to change a users password, redirected from the profile page, the following message has been appearing and had to be implemented in order to continue working. It would seem that the core code should be modified rather than implement this modification. Could someone please verify?

A potentially dangerous Request.QueryString value was detected from the client (error="...$SkinLst="<Use Default Site Sk...").

Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. To allow pages to override application request validation settings, set the requestValidationMode attribute in the httpRuntime configuration section to requestValidationMode="2.0". Example: <httpRuntime requestValidationMode="2.0" />. After setting this value, you can then disable request validation by setting validateRequest="false" in the Page directive or in the <pages> configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case. For more information, see http://go.microsoft.com/fwlink/?LinkI....

Thanx

Thanx

L Douglas
 
New Post
12/30/2010 4:16 PM
 
please follow the advice in the error message and update your web.config to use requestValidationMode="2.0"

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
3/9/2011 5:00 AM
 
cathal connolly wrote:
please follow the advice in the error message and update your web.config to use requestValidationMode="2.0"

 Hello, I was reading through the forum in search for a solution to my problem (dangerousn Request.QueryString error pops up whenever I try to change the portal skin)
I realised that I can run my freshly upgraded 5.6 DNN installation without errors ONLY if I set validateRequest="false" in the pages section. Plus I tried adding requestValidationMode="2.0" to my httpRuntime section in web config and it does work and solve the problem (only if I set validation to False) but a red squiggly line appears under it...

Any ideas as to how I could solve these problems before I try to upgrade my live version from 4.9.5 to 5.6 via 5.4.4...?

Thank you

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...dangerous Request.QueryStringdangerous Request.QueryString


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out