XSS Attack
<script>
$http.post("\transferMoney", {amount: 1000000, toAccount: "111AttackersAccount"});
</script> class MoneyTransactionController: Controller
{
[ValidateInput(false)]
public ActionResult Transfer()
{
//business logic to handle money transfer
return View();
}
}namespace MyMVCApplication.Models
{
public class CodeSample
{
public string SubmittedBy { get; set; }
[AllowHTML]
public string Code { get; set; }
}
}Last updated