Non persistent XSS could be injected in search modules (common and fulltextsearch) via the parameter words and into the login form via the parameter return_to.
Impact
An attacker could use these vulnerabilities to force a victim to execute uncontrolled code. The return_to parameter could also be used to redirect a victim to a untrusted website.
CVSS2 score : 5 (AV:N/AC:L/Au:N/C:N/I:P/A:N)
References
http://cwe.mitre.org/data/definitions/79.html
https://cwe.mitre.org/data/definitions/601.html