Hi Mike,
Thanks for the reply. Actually I am working for a company, where we already have a web application. Now we are trying to implement security in our application. We won't be using any open source API for that, since this decision has already been taken, and its not in my hands. Somebody had done initial analysis using AppScan tool, and found the 17 characters mentioned in the link. Now my manager has asked me to find any additional characters that we will need to encode. So I am just googling out to find any such characters. I have found the characters, that I have mentioned in my earlier post. But I need to confirm those characters. I don't need to encode them, since that part is handled by different team. I just need to provide them my analysis, stating any other disallowed characters, apart from 17 characters mentioned in AppScan test.
Thanks,
Dinesh