Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20445
http://www.vupen.com/english/advisories/2005/0487
http://www.securityfocus.com/bid/13534
http://www.gulftech.org/?node=research&article_id=00073-05052005
http://securitytracker.com/id?1013907
http://secunia.com/advisories/15265