Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.Referenceshttp://securitytracker.com/id?1014901http://secubox.teria.org/index.php?menu=24&action=detail&aid=82http://secunia.com/advisories/16798http://www.securityfocus.com/bid/14818