Hacking DropDownList value

后端 未结 2 460
北恋
北恋 2021-01-19 02:09

I\'ve got a DropDownList and I\'m trying to prevent it from being used as an attack vector. Can I assume that the user is unable to actually change the values of the DDL and

2条回答
  •  难免孤独
    2021-01-19 02:58

    No, you can't assume that.

    You should always consider that all input is untrusted, and treat it appropriately (make sure it is what it should be, and that it is of the right type, and that the current user (or whatever) has access to it, and so on).

提交回复
热议问题