﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Intersoft Community</title><link>http://www.intersoftsolutions.com/Community/</link><description /><generator>http://www.intersoftsolutions.com</generator><language>en</language><copyright>Copyright 2002 - 2015 Intersoft Solutions Corp. All rights reserved.</copyright><ttl>60</ttl><item><title>Webcombo Security issue</title><link>http://www.intersoftsolutions.com/Community/WebCombo/Webcombo-Security-issue/</link><pubDate>Thu, 23 Nov 2023 12:11:16 GMT</pubDate><dc:creator>sphinxg@usa.net</dc:creator><category>Security issue</category><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;I am using Intersoft webcombo in my ASP.Net Web application.&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;I am checking the application security using the tool semgrep for SAST (Static Application Security Testing).&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;While testing I face the below errors. The JavaScript generated by the webcombo is causing the issue .&lt;/p&gt;&lt;p&gt;&lt;span class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak" dir="ltr"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;Please help me to solve these issues.&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;b&gt;Files in which error occured:&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-18.0pt;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:Symbol;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol"&gt;&lt;b&gt;·&lt;/b&gt;&lt;span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-variant-position: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/b&gt;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang="EN-US" style="font-size:10.0pt;
line-height:107%;mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;CoreValidator.js&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:Symbol;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol"&gt;·&lt;span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-variant-position: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang="EN-US" style="font-size:10.0pt;
line-height:107%;mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;Core_DragDrop.js&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:Symbol;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol"&gt;·&lt;span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-variant-position: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang="EN-US" style="font-size:10.0pt;
line-height:107%;mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;ISCore.js&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:Symbol;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol"&gt;·&lt;span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-variant-position: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang="EN-US" style="font-size:10.0pt;
line-height:107%;mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;WebUIValidation.js&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:Symbol;
mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol"&gt;·&lt;span style="font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-alternates: normal; font-kerning: auto; font-optical-sizing: auto; font-feature-settings: normal; font-variation-settings: normal; font-variant-position: normal; font-stretch: normal; font-size: 7pt; line-height: normal; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang="EN-US" style="font-size:10.0pt;
line-height:107%;mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;WebCombo.js&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;!--[if !supportLists]--&gt;&lt;p&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px;"&gt;







&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;b&gt;Error Message 1&lt;/b&gt;:&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;javascript.browser.security.insecure-document-method.insecure-document-method
User controlled data in methods like `innerHTML`, `outerHTML` or
`document.write` is an anti-pattern that can lead to XSS vulnerabilities&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin;background:yellow;
mso-highlight:yellow"&gt;...
e.innerHTML=v;WC40Engine.InvalidateResultBox(f);return
v},WriteCOLs:function(f,d){var&amp;nbsp;
e="";if(f.LayoutSettings.ComboMode=="MultipleColumns"){var
a= ...&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px;"&gt;



&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin;background:yellow;
mso-highlight:yellow"&gt;...
b.innerHTML="&amp;lt;nobr&amp;gt;"+l.Text+"&amp;lt;/nobr&amp;gt;"}}else{var
h=p.Columns;for(var&amp;nbsp; k=0;k&amp;lt;h.length;k++){var
f=h[k];if(f.Hidden&amp;amp;&amp;amp;!f.RenderOnHidden){continue}var q=f ...&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;b&gt;Error Message 2:&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;javascript.lang.security.audit.detect-non-literal-regexp.detect-non-literal-regexp
RegExp() called with a `e` function argument, this might allow an attacker to
cause a Regular Expression Denial-of-Service (ReDoS) within your application as
RegExP blocks the main thread. For this reason, it is recommended to use
hardcoded regexes instead. If your regex is run on user-controlled input,
consider performing input validation or use a regex checking/sanitization
library such as https://www.npmjs.com/package/recheck to verify that the regex
does not appear vulnerable to ReDoS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px;"&gt;

&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:&amp;quot;Calibri&amp;quot;,sans-serif;
mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Calibri;mso-fareast-theme-font:
minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-theme-font:minor-latin;
background:yellow;mso-highlight:yellow;mso-font-kerning:0pt;mso-ligatures:none;
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA"&gt;…RegExp(c.Pattern,"img");g=c.NewValue.match(re);if(g==null){c.NewValue=c.NewValue.replace(new
&amp;nbsp;RegExp("\\s+","g"),"");g=c.NewValue.match(re)}if(g==
...&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;b&gt;Error Message 3:&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;javascript.browser.security.eval-detected.eval-detected
Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic
content. If this content can be input from outside the program, this may be a
code injection vulnerability. Ensure evaluated content is not definable by
external sources.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px;"&gt;

&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:&amp;quot;Calibri&amp;quot;,sans-serif;
mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Calibri;mso-fareast-theme-font:
minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-theme-font:minor-latin;
background:yellow;mso-highlight:yellow;mso-font-kerning:0pt;mso-ligatures:none;
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA"&gt;al(this.getAttribute(name))}}}},_EmulateSelectionModel:function(){Object.defineProperty(HTMLDocument.prototype,"selection",{get:function(){return
w ...&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;b&gt;Error Message 4:&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;
mso-bidi-font-family:Calibri;mso-bidi-theme-font:minor-latin"&gt;javascript.lang.security.audit.incomplete-sanitization.incomplete-sanitization
`h.replace` method will only replace the first occurrence when used with a
string argument ("$"). If this method is used for escaping of
dangerous data then there is a possibility for a bypass. Try to use
sanitization library instead or use a Regex with a global flag.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px;"&gt;

&lt;span lang="EN-US" style="font-size:10.0pt;line-height:107%;font-family:&amp;quot;Calibri&amp;quot;,sans-serif;
mso-ascii-theme-font:minor-latin;mso-fareast-font-family:Calibri;mso-fareast-theme-font:
minor-latin;mso-hansi-theme-font:minor-latin;mso-bidi-theme-font:minor-latin;
background:yellow;mso-highlight:yellow;mso-font-kerning:0pt;mso-ligatures:none;
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA"&gt;replace("$","\\s*\\"+i+"\\s*")}else{if(j=="percent"){h=h.replace(i,"\\s*\\"+i+"\\s*")}}h="(?:^"+h.replace(new
RegExp("\\s*","g"),"")+"$)";return h}
...&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;&lt;br&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;With Regards,&lt;/p&gt;&lt;p style="margin-bottom: 0px; margin-left: 0px; margin-top: 0px;"&gt;Giridhar JG&lt;/p&gt;</description></item><item><title>Regarding XSS issue faced in the web combo.</title><link>http://www.intersoftsolutions.com/Community/WebCombo/Regarding-XSS-issue-faced-in-the-web-combo/</link><pubDate>Tue, 01 Aug 2023 08:33:32 GMT</pubDate><dc:creator>sphinxg@usa.net</dc:creator><description>&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;&lt;br&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;Hi&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;We are facing the below mentioned security issue
in one of our client environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;A significant portion of the XSS test payload
appeared in the web page, but the page's DOM was not modified as expected for a
successful exploit. This result was manually verified to determine its
accuracy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;Kindly find the attached screenshots for
reference(Request and Response).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:normal;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape
 id="Picture_x0020_2" o:spid="_x0000_i1025" type="#_x0000_t75" style='width:6in;
 height:59.5pt;visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:/Users/VELUMA~1.MOO/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span lang="EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Kindly help us to resolve the same&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thanks in advance.&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Regarding XSS issue faced in the web combo.</title><link>http://www.intersoftsolutions.com/Community/WebCombo/Regarding-XSS-issue-faced-in-the-web-combo/</link><pubDate>Tue, 01 Aug 2023 08:31:46 GMT</pubDate><dc:creator>sphinxg@usa.net</dc:creator><description>&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;&lt;br&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;Hi&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;We are facing the below mentioned security issue
in one of our client environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;A significant portion of the XSS test payload
appeared in the web page, but the page's DOM was not modified as expected for a
successful exploit. This result was manually verified to determine its
accuracy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;Kindly find the attached screenshots for
reference(Request and Response).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:normal;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape
 id="Picture_x0020_2" o:spid="_x0000_i1025" type="#_x0000_t75" style='width:6in;
 height:59.5pt;visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:/Users/VELUMA~1.MOO/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span lang="EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Kindly help us to resolve the same&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thanks in advance.&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Regarding XSS issue faced in the web combo.</title><link>http://www.intersoftsolutions.com/Community/WebCombo/Regarding-XSS-issue-faced-in-the-web-combo/</link><pubDate>Tue, 01 Aug 2023 08:31:45 GMT</pubDate><dc:creator>sphinxg@usa.net</dc:creator><description>&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;&lt;br&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;Hi&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;We are facing the below mentioned security issue
in one of our client environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;A significant portion of the XSS test payload
appeared in the web page, but the page's DOM was not modified as expected for a
successful exploit. This result was manually verified to determine its
accuracy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;Kindly find the attached screenshots for
reference(Request and Response).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:normal;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape
 id="Picture_x0020_2" o:spid="_x0000_i1025" type="#_x0000_t75" style='width:6in;
 height:59.5pt;visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:/Users/VELUMA~1.MOO/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span lang="EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Kindly help us to resolve the same&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thanks in advance.&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Regarding XSS issue faced in the web combo.</title><link>http://www.intersoftsolutions.com/Community/WebCombo/Regarding-XSS-issue-faced-in-the-web-combo/</link><pubDate>Tue, 01 Aug 2023 08:30:25 GMT</pubDate><dc:creator>sphinxg@usa.net</dc:creator><category>XSS</category><category>cross-site scripting</category><category>Unencoded characters</category><description>&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;&lt;br&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b&gt;&lt;span lang="EN"&gt;Hi&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN"&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;We are facing the below mentioned security issue
in one of our client environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;A significant portion of the XSS test payload
appeared in the web page, but the page's DOM was not modified as expected for a
successful exploit. This result was manually verified to determine its
accuracy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:115%;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;Kindly find the attached screenshots for
reference(Request and Response).&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:10.0pt;line-height:normal;mso-pagination:
none;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span lang="EN"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape
 id="Picture_x0020_2" o:spid="_x0000_i1025" type="#_x0000_t75" style='width:6in;
 height:59.5pt;visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:/Users/VELUMA~1.MOO/AppData/Local/Temp/msohtmlclip1/01/clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span lang="EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Kindly help us to resolve the same&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;Thanks in advance.&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Webgrid 10 upgrade</title><link>http://www.intersoftsolutions.com/Community/Lounge/Webgrid-10-upgrade/</link><pubDate>Thu, 22 Jun 2023 16:29:47 GMT</pubDate><dc:creator>kalyan2984</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;We are trying to upgrade to Webgrid 10 version, and need support from the Intersoft team. Please let me know if you have any references.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Thank you&lt;/p&gt;</description></item><item><title>Install new version</title><link>http://www.intersoftsolutions.com/Community/Lounge/Install-new-version/</link><pubDate>Sun, 30 Oct 2022 14:49:31 GMT</pubDate><dc:creator>roiu@a-g-r-e.com</dc:creator><description>&lt;p&gt;Hi&lt;br&gt;&lt;br&gt;I'm trying to install new version and i get only error.&lt;br&gt;&lt;span style="font-size: 10pt;"&gt;&lt;br&gt;I&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt;f there is anyone familiar with the subject&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;I would be happy to help, even for a fee.&lt;/span&gt;&lt;/p&gt;</description></item><item><title>WebUi jquery version</title><link>http://www.intersoftsolutions.com/Community/Lounge/WebUi-jquery-version/</link><pubDate>Thu, 15 Sep 2022 05:20:55 GMT</pubDate><dc:creator>roiu@a-g-r-e.com</dc:creator><category>WebUI Studio</category><category>JQuery</category><description>&lt;p&gt;Hi&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoPlainText"&gt;I get errors that maybe related to the jquery version (my
guess)&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class="MsoPlainText"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;span style="font-size: 10pt;"&gt;I tried to find what version is compatible for this
product but I didn't find it.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoPlainText"&gt;What version I need ?&lt;/p&gt;&lt;p class="MsoPlainText"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class="MsoPlainText"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;/p&gt;</description></item><item><title>Is file IEMozBridge.js still required or is it a legacy file that may be deprecated/removed </title><link>http://www.intersoftsolutions.com/Community/Lounge/Is-file-IEMozBridgejs-still-required-or-is-it-a-legacy-file-that-may-be-deprecatedremoved/</link><pubDate>Thu, 25 Aug 2022 07:39:13 GMT</pubDate><dc:creator>mateusz.chabros@volvo.com</dc:creator><description>&lt;p&gt;&lt;span style="background-color: rgb(255, 255, 255); font-size: 13.3333px;"&gt;hello,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="background-color: rgb(255, 255, 255); font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px;"&gt;isnetweb ui&amp;nbsp; is loading the file IEMozBridge.js to support old and deprecated versions of IE and FF.&lt;/span&gt;&lt;/p&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;For example the file loads function document.createStyleSheet.&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;span style="box-sizing: border-box;"&gt;Official documentation states that the method was removed long time ago:&amp;nbsp;&lt;/span&gt;&lt;span style="box-sizing: border-box;"&gt;&lt;a href="#legacy-api-additions-changes-and-removals" style="box-sizing: border-box; cursor: pointer;"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/dev-guides/bg182625(v=vs.85)#legacy-api-additions-changes-and-removals&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;Meaning that any other browser (except for IE) is not supposed to have such method at all.&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;and our web site doesn't support IE but Chrome,&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;b&gt;Is file IEMozBridge.js still required or is it a legacy file that may be deprecated/removed?&lt;/b&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;&lt;div style="box-sizing: border-box; font-family: &amp;quot;Segoe UI VSS (Regular)&amp;quot;, &amp;quot;Segoe UI&amp;quot;, -apple-system, BlinkMacSystemFont, Roboto, &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Ubuntu, Arial, sans-serif, &amp;quot;Apple Color Emoji&amp;quot;, &amp;quot;Segoe UI Emoji&amp;quot;, &amp;quot;Segoe UI Symbol&amp;quot;; font-size: 14px; background-color: rgb(255, 255, 255);"&gt;&lt;br&gt;&lt;/div&gt;</description></item><item><title>Need License Information for WebUI</title><link>http://www.intersoftsolutions.com/Community/WebGrid/Need-License-Information-for-WebUI/</link><pubDate>Sat, 28 May 2022 16:31:44 GMT</pubDate><dc:creator>Bill0208</dc:creator><category>WebGrid</category><category>webui</category><description>&lt;p&gt;I took over a project using the Intersoft WebUI controls.&amp;nbsp; The prevous developer left without documenting the project now I am stuck trying to setup a DEV server without the liocense for the product.&amp;nbsp; I need the license information desperately to move forward.&amp;nbsp;&lt;span style="font-size: 10pt;"&gt;Please help.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;</description></item></channel></rss>