Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/30647
http://www.vupen.com/english/advisories/2006/4789
http://www.securityfocus.com/bid/21438
http://www.kb.cert.org/vuls/id/989144
http://sla.ckers.org/forum/read.php?3%2C3109