Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
- http://securityreason.com/securityalert/8439
- http://www.packetstormsecurity.org/1009-advisories/ZSL-2010-4962.txt
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4962.php
No PoCs found on GitHub currently.