CVE-2006-2605
Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.
Date published : 2006-05-25
http://www.securityfocus.com/bid/18084
http://www.securityfocus.com/archive/1/434821/100/0/threaded