<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.infopathdev.com:443/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>General</title><link>https://www.infopathdev.com:443/forums/41.aspx</link><description>If you're not sure where to ask your question, ask it here. If necessary, our moderators will make sure it gets classified in the correct board.</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP3 (Build: 31118.962)</generator><item><title>Re: Restriction of Cross-site Scripting(Injection)</title><link>https://www.infopathdev.com:443/forums/thread/6602.aspx</link><pubDate>Thu, 17 Mar 2005 05:17:23 GMT</pubDate><guid isPermaLink="false">033a2e2d-04e2-4a9d-be01-a4634161eefd:6602</guid><dc:creator>Sudheer</dc:creator><slash:comments>0</slash:comments><comments>https://www.infopathdev.com:443/forums/thread/6602.aspx</comments><wfw:commentRss>https://www.infopathdev.com:443/forums/commentrss.aspx?SectionID=41&amp;PostID=6602</wfw:commentRss><description>Anybody has ever faced this issue.</description></item><item><title>Restriction of Cross-site Scripting(Injection)</title><link>https://www.infopathdev.com:443/forums/thread/4588.aspx</link><pubDate>Wed, 16 Mar 2005 04:34:54 GMT</pubDate><guid isPermaLink="false">033a2e2d-04e2-4a9d-be01-a4634161eefd:4588</guid><dc:creator>Sudheer</dc:creator><slash:comments>0</slash:comments><comments>https://www.infopathdev.com:443/forums/thread/4588.aspx</comments><wfw:commentRss>https://www.infopathdev.com:443/forums/commentrss.aspx?SectionID=41&amp;PostID=4588</wfw:commentRss><description>In our tool, Infopath has been used in integration with WebApplication.  On button click in Aspx page I am opening an infopath and Data editing is totally using Infopath and after submission of data in infopath showing the same content in readonly mode in aspx. &lt;br /&gt;&lt;br /&gt;So in this scenario, when I enter some junk like( &amp;lt;script&amp;gt; alert(“a”) &amp;lt;/script&amp;gt;) in one of editable controls and submit data in infopath and try to see the data in aspx  page getting the alert Message. So Cross-site scripting(Injection ) is happening. Is there any direct way to restrict this type of validation. &lt;br /&gt;&lt;br /&gt;Can any body please suggest how I can handle this scenario. It stood as blocking Security Bug.&lt;br /&gt;I am using Jscript for Coding with infopath.&lt;br /&gt;&lt;br /&gt;Any ideas can be appreciated.&lt;br /&gt;&lt;br /&gt;Thanks in Advance&lt;br /&gt;</description></item></channel></rss>