Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000230.1-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1