A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.
https://packetstormsecurity.com/files/177239/Dotclear-2.29-Cross-Site-Scripting.html