(Copied from my answer on StackOverflow ). No. HtmlEncode simply does NOT cover all XSS attacks. Encoding is the correct solution, but not always HTML ...
確定! 回上一頁