-= DDSi Security Advisory =- March 24, 2006 ---------------------------------------------------------------- Vendor: Raindance Communications, Inc. Raindance offers audio and web conferencing solutions for more effective web meetings. Integrated web, audio and internet video conferencing makes online meetings and webinars easier and more productive. Product: Raindance Web Conferencing Pro. Vulnerability : XSS in browser compatibility check. Meeting requests may be sent to unsuspecting party with malicious code. Location: http://company.raindance.com/check/failed? browser=1:%3Cscript%3Ewindow.alert(%22a%22)%3C/script%3E &passedurl=/iccdocs/passedtest.shtml Vendor communication history: March 13 initial contact ( webmaster ) March 16 second attempt contact techsupport March 17 automatic ticket opened March 23 still no techsupport engineer assigned. Email asking for status sent. March 24. No response. Public release. Dimitry Snezhkov. DDSi.