I'm getting the following error in ASP NET 4:
A potentially dangerous Request.Path value was detected from the client (<).
I have read that I need to use requestValidationMode="2.0" in my Web.config:
<system.web>
<compilation debug="true" targetFramework="4.0" />
<httpRuntime requestValidationMode="2.0" />
</system.web>
So my method looks like:
[ValidateInput(false)]
public ActionResult Search(string query, string type){
//method body
return result;
}
It works great. However, I cannot modify my Web.config file because many other applications rely on this file and it may cause a security vulnerability or an error somewhere else.
My application is secure enough to accept special characters, but I cannot say the same for the rest of the system being developed. Is there an alternative to accept special characters as input in my method?
Example:
www.mydomain.com/search/query/<myquery<ffoo/type/dept