I can't PM you for some reason, must be my low karma. I found a reflected XSS vulnerability since it doesn't really matter for this site, I'll paste it here, I hope you don't mind.Just html encoding the <, >, &, " characters will fix it.<p><a href="http://www.ftfysearch.com/search?q=%3C%2Ftitle%3E%3C%2Fhead%3E%3Cbody%3E%3Cscript%3Ealert%28%22hi+friend+from+HN%22%29%3B+%3C%2Fscript%3E+%3C%2Fbody%3E+%3C%2Fhtml%3E" rel="nofollow">http://www.ftfysearch.com/search?q=%3C%2Ftitle%3E%3C%2Fhead%...</a>