DSChat <= 1.0 XSS May 22 2006 07:07PM
zerogue gmail com
DSChat <= 1.0 XSS

Discovered by: Nomenumbra

Date: 21/5/2006

impact:moderate (possible defacement)

DSChat is a PHP-based chatscript which does no filtering

against XSS whatsoever, thus allowing anyone to insert

html or javascript in the chatbox.


