Debian Security Advisory 1882-1 – It was discovered that xapian-omega, a CGI interface for searching xapian databases, is not properly escaping user supplied input when printing exceptions. An attacker can use this to conduct cross-site scripting attacks via crafted search queries resulting in an exception and steal potentially sensitive data from web applications running on the same domain or embedding the search engine into a website.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/81126/dsa-1882-1.txt
Source: https://packetstormsecurity.com/files/81126/Debian-Linux-Security-Advisory-1882-1.html