Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/29183
http://www.vupen.com/english/advisories/2006/3779
http://www.sixapart.com/movabletype/news/2006/09/mt_333-mte_103_updates.html
http://www.securityfocus.com/bid/20228