<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to support Cross-Frame Scripting ( 11293 ) problem in Other HPE Product Questions</title>
    <link>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091959#M4333</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Manager lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1181977" target="_self"&gt;&lt;SPAN class=""&gt;Parvez_AL&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Wed, 17 Jun 2020 02:11:41 GMT</pubDate>
    <dc:creator>Trung107</dc:creator>
    <dc:date>2020-06-17T02:11:41Z</dc:date>
    <item>
      <title>Need to support Cross-Frame Scripting ( 11293 ) problem</title>
      <link>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091717#M4331</link>
      <description>&lt;P&gt;Hi Bro,&lt;/P&gt;&lt;P&gt;I'm used WebInspect, and it&amp;nbsp;&lt;SPAN&gt;detects my website has&amp;nbsp;Cross-Frame Scripting Problem (Cross-Frame Scripting ( 11293 )).&amp;nbsp;&lt;/SPAN&gt;But even my response header has X-Frame-Options &amp;amp; Content-Security-Policy: frame-ancestors setting,&lt;/P&gt;&lt;P&gt;WebInspect still&amp;nbsp;&lt;SPAN&gt;detects the same problem.&amp;nbsp; You can see the report file that contains the issue&amp;nbsp; &lt;SPAN class="fontstyle0"&gt;Cross-Frame Scripting ( 11293 ) here&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;A title="Report file" href="https://drive.google.com/file/d/1Bf-MY80YI8_usmCb-gtjNL6VY_h6pol6/view?usp=sharing" target="_blank" rel="noopener"&gt;report file&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please help me resolve that.&lt;BR /&gt;Is any way to resolve it? So I think that was obviously false positives.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Scan information:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Policy: Standard&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Scan Version: 20.1.0.199&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Scan Type: Site&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;High Issues
Cross-Frame Scripting ( 11293 ) View Description
CWE: 1021
Kingdom: Security Features
Page: https://10.1.33.17:443/&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Request:&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;GET / HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
Pragma: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:30.0) Gecko/20100101
Firefox/58.0
Host: 10.1.33.17
Connection: Keep-Alive
X-WIPP: AscVersion=20.1.0.199
X-Scan-Memo:
Category="Crawl";SID="2CF765E6D8D95CDB61F57141B17462A6";SessionType="Externa
lAddedToCrawl";CrawlType="None";AttackType="None";OriginatingEngineID="00000
000-0000-0000-0000-000000000000";tid="109";tt="31";
X-RequestManager-Memo: sid="67";smi="0";sc="1";ID="3dad46cc";
X-Request-Memo: ID="86fc50f6";sc="1";tid="106";
Cookie: CustomCookie=WebInspect148724ZXE9B2988179734CA6A2CF0DC556B11AD3YFD5F
R&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Response:&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;HTTP/1.1 200 OK
Cache-Control: no-cache, no-store,private, max-age=3600, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Content-Length: 15548
Set-Cookie:
.AspNetCore.Antiforgery.c_12tiZU3jA=CfDJ8N8w1XEX_wxJuzUyQXra96u2ltEear86diCa
FvrnuzWHPfeugmNneN297MliJ_8aNt27154edOJ0vrV6k1VD6Sj1ue0z1rOTZaDql9YznwdzsVqFbUOj5Vfyf
O8zXcVKpp1IoDnnVudgolF8rVQbLA; path=/; samesite=strict; httponly
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src
'self' 'unsafe-inline'; img-src 'self' data:
https://10.1.33.17:443/Resources/; font-src 'self' data:; object-src
'none'; frame-ancestors 'none'; base-uri 'none';
Date: Mon, 15 Jun 2020 08:34:10 GMT&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 16 Jun 2020 11:32:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091717#M4331</guid>
      <dc:creator>Trung107</dc:creator>
      <dc:date>2020-06-16T11:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need to support Cross-Frame Scripting ( 11293 ) problem</title>
      <link>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091748#M4332</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Webinspect is part of a different company named " Micro Focus " . So you will need to repost your question to the Micro Focus Community at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.softwaregrp.com/" target="_blank" rel="nofollow noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer"&gt;https://community.softwaregrp.com/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 12:46:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091748#M4332</guid>
      <dc:creator>Parvez_Admin</dc:creator>
      <dc:date>2020-06-16T12:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Need to support Cross-Frame Scripting ( 11293 ) problem</title>
      <link>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091959#M4333</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Manager lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1181977" target="_self"&gt;&lt;SPAN class=""&gt;Parvez_AL&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Jun 2020 02:11:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/other-hpe-product-questions/need-to-support-cross-frame-scripting-11293-problem/m-p/7091959#M4333</guid>
      <dc:creator>Trung107</dc:creator>
      <dc:date>2020-06-17T02:11:41Z</dc:date>
    </item>
  </channel>
</rss>

