The last two days I did an ASP.NET security training for a customer. One discussion was how ASP.NET control handle (or don’t) output encoding – especially how inconsistent their behavior is.
Five minutes ago I found this post by Alex – and he links to this table. Wow.