What are possible reasons for "Potentially dangerous Request.RawUrl"?
03:12 27 Oct 2009

In an asp.net web forms application we get an error message with "A potentially dangerous Request.RawUrl" sometimes, but I cannot find the source of it.

What are the possible reasons for this exception?


Some details from our case:

Event message: A validation error has occurred

Exception type: System.Web.HttpRequestValidationException

Exception message: A potentially dangerous Request.RawUrl value was 
detected from the client (="..._Combin%20%20%20%20%20%2...").

Request URL: https://somesite/somepage.aspx
?_TSM_HiddenField_=ctl00_sm1_HiddenField
&_TSM_Combin%20
%20%20%20%20%20%20%20%20

I recognise the part with TSM_HiddenField in the html of the generated page:

 

... so it seems to be related to AjaxControlToolkit in this case, but how can this exception happen?

(It happens when a user is logged in, so I doubt there is some crawler or hack attempt involved...)

asp.net exception webforms rawurl