Click here to Skip to main content
15,887,676 members
Home / Discussions / ASP.NET
   

ASP.NET

 
GeneralRe: Error: The resource cannot be found. Pin
Member 876166711-Sep-14 9:15
Member 876166711-Sep-14 9:15 
AnswerRe: Error: The resource cannot be found. Pin
ZurdoDev11-Sep-14 9:31
professionalZurdoDev11-Sep-14 9:31 
GeneralRe: Error: The resource cannot be found. Pin
Member 876166711-Sep-14 9:33
Member 876166711-Sep-14 9:33 
SuggestionRe: Error: The resource cannot be found. Pin
Richard Deeming11-Sep-14 9:49
mveRichard Deeming11-Sep-14 9:49 
GeneralRe: Error: The resource cannot be found. Pin
Member 876166711-Sep-14 10:16
Member 876166711-Sep-14 10:16 
GeneralRe: Error: The resource cannot be found. Pin
Richard Deeming12-Sep-14 1:37
mveRichard Deeming12-Sep-14 1:37 
GeneralRe: Error: The resource cannot be found. Pin
Member 876166713-Sep-14 8:34
Member 876166713-Sep-14 8:34 
GeneralRe: Error: The resource cannot be found. Pin
Richard Deeming15-Sep-14 1:56
mveRichard Deeming15-Sep-14 1:56 
That looks very much like the original code you posted. You're missing all of the required encoding.

For example, try entering a username of <script>alert("Test")</script> - you'll either get a message box pop up when the success page loads, or your browser will prevent access to the page with a warning about cross-site scripting.

You need to encode the value according to the context:

register.aspx.vb:
VB
Dim name As String = HttpUtility.UrlEncode(username.Text)
Dim target As String = String.Format("~/Success.aspx?Name={0}", name)
Response.Redirect(target, True)


success.aspx.vb:
VB
Public Class success
    Inherits System.Web.UI.Page

    Protected Sub Page_Load(ByVal sender As Object, ByVal e As System.EventArgs) Handles Me.Load

        Dim theName As String = Request.QueryString("Name")
        If Not String.IsNullOrEmpty(theName) Then
            Dim encodedName As String = HttpUtility.HtmlEncode(theName)
            Name.Text = String.Format("{0}, ", encodedName)
        End If

    End Sub

End Class




"These people looked deep within my soul and assigned me a number based on the order in which I joined."
- Homer


GeneralRe: Error: The resource cannot be found. Pin
Member 876166715-Sep-14 2:30
Member 876166715-Sep-14 2:30 
GeneralRe: Error: The resource cannot be found. Pin
ZurdoDev11-Sep-14 10:53
professionalZurdoDev11-Sep-14 10:53 
QuestionMVC jQuery dropdown context menu Pin
Stephen Holdorf11-Sep-14 3:35
Stephen Holdorf11-Sep-14 3:35 
QuestionViewstate spider web Pin
Ali Al Omairi(Abu AlHassan)10-Sep-14 22:20
professionalAli Al Omairi(Abu AlHassan)10-Sep-14 22:20 
AnswerRe: Viewstate spider web Pin
thatraja11-Sep-14 2:09
professionalthatraja11-Sep-14 2:09 
AnswerRe: Viewstate spider web Pin
Sibeesh KV29-Sep-14 1:21
professionalSibeesh KV29-Sep-14 1:21 
QuestionCurrent date Pin
Otekpo Emmanuel10-Sep-14 12:39
Otekpo Emmanuel10-Sep-14 12:39 
AnswerRe: Current date Pin
Ali Al Omairi(Abu AlHassan)10-Sep-14 22:08
professionalAli Al Omairi(Abu AlHassan)10-Sep-14 22:08 
GeneralRe: Current date Pin
Otekpo Emmanuel10-Sep-14 23:23
Otekpo Emmanuel10-Sep-14 23:23 
GeneralRe: Current date Pin
Ali Al Omairi(Abu AlHassan)11-Sep-14 1:29
professionalAli Al Omairi(Abu AlHassan)11-Sep-14 1:29 
GeneralRe: Current date Pin
Otekpo Emmanuel11-Sep-14 3:15
Otekpo Emmanuel11-Sep-14 3:15 
GeneralRe: Current date Pin
Richard Deeming11-Sep-14 3:50
mveRichard Deeming11-Sep-14 3:50 
GeneralRe: Current date Pin
Otekpo Emmanuel11-Sep-14 7:45
Otekpo Emmanuel11-Sep-14 7:45 
GeneralRe: Current date Pin
Richard Deeming11-Sep-14 7:50
mveRichard Deeming11-Sep-14 7:50 
GeneralRe: Current date Pin
Otekpo Emmanuel12-Sep-14 12:52
Otekpo Emmanuel12-Sep-14 12:52 
GeneralRe: Current date Pin
Richard Deeming15-Sep-14 1:49
mveRichard Deeming15-Sep-14 1:49 
QuestionPerformance with loading data to DB2 Pin
byka10-Sep-14 2:59
byka10-Sep-14 2:59 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.