Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-0187
http://www.securityfocus.com/bid/21977