Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.Referenceshttp://phpwebsite.appstate.edu/blog/2143http://www.securityfocus.com/archive/1/485704/100/0/threadedhttp://www.securityfocus.com/bid/27090http://secunia.com/advisories/28303https://exchange.xforce.ibmcloud.com/vulnerabilities/39391http://securityreason.com/securityalert/3511