CVE-2006-5069
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Date published : 2006-09-27
http://www.securityfocus.com/bid/20173
http://www.securityfocus.com/archive/1/446885/100/0/threaded