Cross-site scripting (XSS) vulnerability in index.php in VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter.Referenceshttp://secunia.com/advisories/38701http://packetstormsecurity.org/1002-exploits/vss-xss.txt