2 Replies - 666 Views - Last Post: 11 February 2010 - 02:32 AM Rate Topic: -----

#1 ่jupzyjang  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 1
  • Joined: 09-February 10

about embeded code in ASP.NET

Posted 09 February 2010 - 03:12 AM

้hi!

For now,My problem is about embeded code in ASP.NET(use vb.net)
In this page have form for store data to database

this is my url http://127.0.0.1/textinput.aspx

The page has textbox with embeded code of flash

like this
<embed src=""testxml2.swf"" quality=""high"" bgcolor=""#ffffff"" width=""500"" height=""380"" name=""testxml2"" align=""middle"" allowScriptAccess=""sameDomain"" allowFullScreen=""false"" type=""application/x-shockwave-flash"" pluginspage=""http://www.macromedia.com/go/getflashplayer"" />

My problem is when I click the submit button to link page

It error like this:
A potentially dangerous Request.QueryString value was detected from the client (txtEmbed="<embed src="testxml2...").

and new url page is like this:
http'://127.0.0.1/textinput.aspx?__VIEWSTATE=%2FwEPDwUJMjc0NzY0Nzc5ZGSsGsiW%2FfaHvrJSgkMx13%2FnrIOztg%3D%3D&__EVENTVALIDATION=%2FwEWDwKXhtG4BQKs%2B5bqDwKl1bK4CQK1qbSRCwKE8%2F26DAKfy7n5DwK0ubPaBALr6%2FaZCALv7ITZAgLClsKXBwLv3qCADQL8v%2FmQBwKl0%2FWtBAKct7iSDALAhKyVCMd%2B0HNt7LFUsDVusR6gUuD167cN&txtID=&txtUsername=&txtPassword=&txtEmail=&txtHospitalName=&txtHospitalPhoneNO=&txtFaxNo=&txtAddress=&txtDistrict=&txtProvince=&txtZipCode=&txtUrlContact=&btnSave=Submit&txtEmbed=%3Cembed+src%3D%22testxml2.swf%22+quality%3D%22high%22+bgcolor%3D%22%23ffffff%22+width%3D%22500%22+height%3D%22380%22+name%3D%22testxml2%22+align%3D%22middle%22+allowScriptAccess%3D%22sameDomain%22+allowFullScreen%3D%22false%22+type%3D%22application%2Fx-shockwave-flash%22+pluginspage%3D%22http%3A%2F%2Fwww.macromedia.com%2Fgo%2Fgetflashplayer%22+%2F%3E

SO,It's have embeded code in this New URL
and I try on this txtEmbed.text = "" it error too
but If i delete embeded code in textbox and submit it's work.

I dont know the problem is
Cloud you tell me please.

This post has been edited by ่jupzyjang: 09 February 2010 - 03:15 AM


Is This A Good Question/Topic? 0
  • +

Replies To: about embeded code in ASP.NET

#2 Jayman  Icon User is offline

  • Student of Life
  • member icon

Reputation: 418
  • View blog
  • Posts: 9,532
  • Joined: 26-December 05

Re: about embeded code in ASP.NET

Posted 09 February 2010 - 08:44 AM

Post your code for the submit button.

For some reason you are putting your Viewstate in the Query String.
Was This Post Helpful? 0
  • +
  • -

#3 SanjitN  Icon User is offline

  • New D.I.C Head

Reputation: 2
  • View blog
  • Posts: 13
  • Joined: 11-February 10

Re: about embeded code in ASP.NET

Posted 11 February 2010 - 02:32 AM

View Post่jupzyjang, on 09 February 2010 - 02:12 AM, said:

้It error like this:
A potentially dangerous Request.QueryString value was detected from the client (txtEmbed="<embed src="testxml2...").


Read this
This is a security feature. You cannot send HTML Code through the textbox to prevent injection attacks.

You can try sending the code using a LABEL Control.
Was This Post Helpful? 0
  • +
  • -

Page 1 of 1