Debian Security Advisory 1429-1 – Michael Skibbe discovered that htdig, a WWW search system for an intranet or small internet, did not adequately quote values submitted to the search script, allowing remote attackers to inject arbitrary script or HTML into specially crafted links.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61740/dsa-1429-1.txt
Source: https://packetstormsecurity.com/files/61740/Debian-Linux-Security-Advisory-1429-1.html

