--- mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs.orig 2012-08-11 18:48:46.946062473 +0300 +++ mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs 2012-08-11 18:49:44.885480363 +0300 @@ -42,7 +42,7 @@ throw new HttpException (403, "This type of page is not served.", - req != null ? req.Path : null, + req != null ? HttpUtility.HtmlEncode (req.Path) : null, description); }