CVE-2009-1620
Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.
Date published : 2009-05-12
http://www.securityfocus.com/bid/34722
http://www.securityfocus.com/archive/1/503014/100/0/threaded