You can take a look at this
Think about this, since not only the request from .aspx pages is checked for requests by malicious users, but not all requests. This can lead to websites breaking their functionality if they were upgraded from 2.0 to 4.0.
To be honest, I don't understand why a particular request fails. So far I have just returned 4.0 applications back to check 2.0
<httpRuntime requestValidationMode="2.0" />
citronas
source share