Especially if it's banking related... What happens if you import a item_text from cell C5... But cell C5 says something like alert('XSS!'), with possible variations to mask the < symbol.. You're not protected by asp.net anymore "A potentially dangerous...". There is no form. You must handle ALL validation in the code I assume... NEVER trust user uploads...
MehGerbil wrote:
If you knew how shoddy banks are with data you'd probably hide your money under a pillow.
Trust me, I know. I'm a programmer, refusing to access his own bank account via web... So I used to go directly (old school style) for transfers; but then last time I get these clueless computertards doing it for me, from their computer! (more likely to be infected than mine). I also saw how easily I could have, well, while she was, well, don't wanna give any ideas (puts infected usb back in pocket)...