Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.
http://www.securityfocus.com/archive/1/348641/30/21790/threaded
http://www.securityfocus.com/archive/1/330676
http://www.debian.org/security/2003/dsa-355